Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CISA Lists Seven New Vulnerabilities Amidst Rising Cyber Threats

CISA Lists Seven New Vulnerabilities Amidst Rising Cyber Threats

Posted on September 3, 2026 By CWS

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities (KEV) catalog, adding seven critical security weaknesses that have recently come under attack. This update was announced on Wednesday, highlighting the growing threat landscape in cybersecurity.

The vulnerabilities include serious threats such as a server-side request forgery in SonicWall SMA 1000 Appliances and a command injection flaw in Kestra OSS, both with the highest CVSS score of 10.0. These weaknesses could potentially allow unauthorized access and remote code execution by attackers.

SonicWall and Sangoma Vulnerabilities Under Fire

Among the vulnerabilities, CVE-2026-83548 and CVE-2026-83549 in SonicWall SMA 1000 Appliances have drawn attention due to their severe impact. These flaws allow unauthorized operations and arbitrary command execution, leading to significant security breaches.

Similarly, a critical SQL injection vulnerability, CVE-2026-9586, in Sangoma Switchvox could enable attackers to manipulate backend databases, potentially resulting in remote code execution and further exploitation of systems.

Threats to JFrog Artifactory and Kestra OSS

The JFrog Artifactory is also vulnerable to improper authentication, as identified in CVE-2026-82329. This flaw could grant attackers administrative privileges, exacerbating the potential damage from unauthorized network access.

In the case of Kestra OSS, CVE-2026-49869 allows attackers to execute arbitrary workflows, leading to extensive breaches including cryptocurrency mining and data theft. These vulnerabilities are of particular concern due to the potential impact on critical infrastructure.

AI Infrastructure and Persistent Threats

The highlighted vulnerabilities reveal a trend towards targeting AI infrastructure. For example, flaws in LiteLLM are being exploited to deploy cryptocurrency miners and acquire sensitive data. The ongoing attacks emphasize the necessity for robust security measures in AI systems.

Federal agencies have been advised to prioritize patching these vulnerabilities, especially given the aggressive tactics of threat actors. The deadline for updates is set for September 16, 2026, for most vulnerabilities, highlighting the urgency of the situation.

As cyber threats become increasingly sophisticated, organizations must stay vigilant and proactive in their security efforts. Monitoring and updating AI workloads and backend systems are crucial steps in safeguarding against these persistent threats.

The Hacker News Tags:AI infrastructure, CISA, cryptocurrency mining, Cybersecurity, Hacking, improper authentication, JFrog Artifactory, Kestra OSS, LiteLLM, reverse shells, SonicWall, SQL injection, Threat Actors, Vulnerabilities

Post navigation

Previous Post: Claude AI Enhances macOS and Windows Functionality
Next Post: Pegasus Zero-Click Spyware Targeted Serbian Activists

Related Posts

MSS Claims NSA Used 42 Cyber Tools in Multi-Stage Attack on Beijing Time Systems MSS Claims NSA Used 42 Cyber Tools in Multi-Stage Attack on Beijing Time Systems The Hacker News
CL-STA-0969 Installs Covert Malware in Telecom Networks During 10-Month Espionage Campaign CL-STA-0969 Installs Covert Malware in Telecom Networks During 10-Month Espionage Campaign The Hacker News
Critical Linux Flaw GhostLock Allows Root Access Critical Linux Flaw GhostLock Allows Root Access The Hacker News
Sneaky 2FA Phishing Kit Adds BitB Pop-ups Designed to Mimic the Browser Address Bar Sneaky 2FA Phishing Kit Adds BitB Pop-ups Designed to Mimic the Browser Address Bar The Hacker News
Trend Micro Apex Central RCE Flaw Scores 9.8 CVSS in On-Prem Windows Versions Trend Micro Apex Central RCE Flaw Scores 9.8 CVSS in On-Prem Windows Versions The Hacker News
Tengu Botnet Uses Watchdog to Restart Linux Devices Tengu Botnet Uses Watchdog to Restart Linux Devices The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Urgent Chrome Update Fixes Critical 0-Day Vulnerability
  • Botnet Disruption Successes and DDoS Adaptation
  • GPT-6 Astra Unveiled: Revolutionizing Cybersecurity Testing
  • Affordable SweepLED Device Detects Hidden Cameras in Hotels
  • FBI Investigates Massive Driver’s License Leak on Dark Web

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Urgent Chrome Update Fixes Critical 0-Day Vulnerability
  • Botnet Disruption Successes and DDoS Adaptation
  • GPT-6 Astra Unveiled: Revolutionizing Cybersecurity Testing
  • Affordable SweepLED Device Detects Hidden Cameras in Hotels
  • FBI Investigates Massive Driver’s License Leak on Dark Web

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark