CISA Known Exploited Vulnerabilities
KEV additions — September 2026
7 CVEs entered the KEV catalog in September 2026.
Added September 4, 20261
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2026-85046 | Google Chromium V8 Type Confusion Vulnerability | 8.8 | 0.5 % | September 18, 2026 |
Added September 2, 20266
| CVE | Vulnerability | CVSS | EPSS | Due date |
|---|---|---|---|---|
| CVE-2026-48710 | Kludex Starlette HTTP Request/Response Smuggling Vulnerability | 6.5 | 0.0 % | September 16, 2026 |
| CVE-2026-59822 | BerriAI LiteLLM Improper Authentication Vulnerability | — | 0.2 % | September 16, 2026 |
| CVE-2026-82329 | JFrog Artifactory Improper Authentication Vulnerability | 9.8 | 0.4 % | September 5, 2026 |
| CVE-2026-83548 | SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability | 10 | 0.3 % | September 5, 2026 |
| CVE-2026-83549 | SonicWall SMA1000 Appliances OS Command Injection Vulnerability | 7.8 | 0.9 % | September 5, 2026 |
| CVE-2026-9586 | Unauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMB | — | 0.4 % | September 5, 2026 |