CISA added seven actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, and researchers are watching attackers turn them into reverse shells and crypto miners. The list reads like a who’s-who of enterprise infrastructure, and if any of it is in your estate, KEV is telling you to patch it first.
What is on the list
The seven span very different products but one theme: internet-facing infrastructure. They include a SonicWall SMA 1000 server-side request forgery flaw rated CVSS 10.0 (CVE-2026-83548), the JFrog Artifactory authentication bypass (CVE-2026-82329), an unauthenticated SQL injection in Sangoma Switchvox (CVE-2026-9586, CVSS 9.3), and flaws in the Python web stack, Starlette, the Kestra orchestration platform and the LiteLLM AI gateway.
Attackers are already weaponising several of them to drop reverse shells and minted admin tokens, and the Qilin ransomware crew has been tied to the LiteLLM chain. A CVE on KEV is not theoretical, it means confirmed exploitation in the wild right now.
Why KEV should drive your patching
Most teams drown in thousands of open CVEs and patch by CVSS score, which is a poor proxy for real risk. KEV cuts through the noise: these are being used today, so they jump the queue. Turning that signal into action, mapping which of your exposed systems carry a KEV flaw, is the core of external network penetration testing, and running it as a repeatable, provable process is what vulnerability management delivers.
What to do now
- Cross-reference the seven new KEV entries against your asset inventory and patch the matches on a KEV-first schedule, not a CVSS-first one.
- Hunt for the noted post-exploitation behaviour: unexpected outbound connections (reverse shells) and CPU spikes (miners), the job of a managed SOC.
- Prioritise internet-facing systems first, then confirm what an attacker could reach with a red team assessment.
- If you find an active intrusion, contain it with data breach response.
The takeaway
You cannot patch everything, so patch what is being exploited. KEV is the industry’s shared shortlist of what attackers are using today, wiring it into your prioritisation, and testing whether those paths are open in your environment, is the highest-leverage move in vulnerability management. Not sure which of these you are exposed to? A penetration test will tell you.
Tell us what you're running
Scoping is free. We reply within one business day, and under 30 minutes for active incidents.
