Future TechnologyFuture Technology
SECURITY

CISA KEV, September 2026: Seven Exploited Flaws, and Attackers Are Hunting AI Servers

· 2 min read · By Future Technology

Key takeaways

  • CISA added seven vulnerabilities to its Known Exploited Vulnerabilities catalogue in early September, with reverse shells and crypto miners in the follow-on activity
  • SonicWall SMA 1000 CVE-2026-83548 scores a perfect CVSS 10.0 for pre-authentication server-side request forgery
  • Attackers hitting exposed RAGFlow instances are stealing LLM provider keys and metadata rather than deploying ransomware

A perfect 10.0. That is the CVSS score on SonicWall SMA 1000 CVE-2026-83548, one of seven vulnerabilities CISA added to its Known Exploited Vulnerabilities catalogue in early September. Perfect scores are rare, and this one is pre-authentication server-side request forgery, so no credentials are needed to start.

The CISA KEV additions worth acting on first

Alongside the 10.0, SonicWall SMA 1000 carries CVE-2026-83549 at 7.8 for post-authentication command injection. Sangoma Switchvox CVE-2026-9586 scores 9.3 for unauthenticated SQL injection straight into the backend PostgreSQL database.

The follow-on activity is the ordinary kind: reverse shells and crypto miners, dropped by people scanning for whatever was published this week. CISA's bulletin lists the rest, and the pattern behind them has not changed in years. Known flaws, unpatched, exploited at scale.

Attackers have started hunting AI infrastructure

The newer part is what sits next to those seven. Exposed RAGFlow instances are being hit through CVE-2026-45312, CVE-2026-28797, CVE-2026-24770 and two flaws carried over from 2025, and the payoff is credential theft rather than ransomware. Attackers are taking LLM provider keys and metadata, then spending someone else's API budget on an account nobody is watching.

That reframes what a RAG deployment is. An internal document search box also holds keys to paid model access, which makes it roughly as attractive a target as a domain controller. Most of the people running one deployed it as a weekend experiment and never took it off the internet. The shape of the problem is familiar from agent tooling that reached places it was never meant to.

So: what to check today

Patch the SonicWall and Switchvox boxes first, because those are being exploited now rather than theoretically. Then find every AI service you have exposed, RAGFlow or otherwise, and confirm it is not reachable from the open internet. Rotate the provider keys sitting inside them and set spend limits, which caps the damage when a key does walk.

It is the same hygiene problem as the 943 patches Oracle shipped last month and the hypervisor escape before it. The flaw gets published, and the gap between publication and patching is the entire attack window.

The part worth watching is whether AI infrastructure gets hardening guidance of its own. Right now people are defending it with instincts built for web servers.

The biggest tech story, explained in 3 minutes every weekday. Choose your briefings →

Free. No spam. Unsubscribe in one click.

Enjoyed this? Get the briefing.

One email, every weekday: the top story, a useful tool, and what matters in tech - in under 3 minutes.

More from Future Technology

EVs

How to Check the CISA KEV Catalog and Find Out What Is Being Exploited Today

EVs

Magna Bets Big on Battery Swapping With an Extra 35 Million Dollars for Yuma Energy

EVs

Galaxy S26 FE Price and Specs: Samsung Landed at $699, Not $799

EVs

CISA Added Four Actively Exploited Flaws to KEV, Including a 9.8 in macOS Screen Sharing