Future TechnologyFuture Technology
SECURITY

Ten exploited flaws hit the CISA KEV catalogue in seven days

· 3 min read · By Future Technology

Key takeaways

  • CISA added ten actively exploited vulnerabilities to the KEV catalogue between 31 August and 6 September 2026, seven of them in one batch
  • CVE-2026-83548 in SonicWall SMA 1000 scores a full 10.0 and requires no authentication
  • CVE-2026-9586 in Sangoma Switchvox is being chained with CVE-2026-82329 to drop reverse shells and crypto miners
  • The common thread is remote access appliances, the boxes deliberately exposed to the internet

Ten actively exploited vulnerabilities entered the CISA Known Exploited Vulnerabilities catalogue between 31 August and 6 September. Seven of them arrived in a single batch.

That is a high water mark for a seven day window, and the additions are not scattered evenly across the software stack. Most of them sit in remote access appliances, the boxes organisations deliberately expose to the internet so staff can work from somewhere else.

The CISA KEV September 2026 entries that matter most

CVE-2026-83548 is the headline. It is a server side request forgery in SonicWall SMA 1000 appliances scoring a full 10.0, and it needs no authentication at all. Its companion, CVE-2026-83549, is a 7.8 post-authentication command injection that gives code execution. SonicWall has confirmed it investigated a case indicating active exploitation of both.

Next to them sits CVE-2026-9586, a 9.3 SQL injection in Sangoma Switchvox. Attackers have been chaining it with CVE-2026-82329 to drop reverse shells and cryptocurrency miners on the underlying host.

A 10.0 with no authentication requirement means an attacker needs nothing except the ability to reach the appliance. There is no credential to steal first and no user to phish. If the box answers on the internet, it is in scope.

Why remote access appliances keep showing up

These devices get hunted first because they have to be reachable by design. A VPN concentrator or an SSL portal that only works from inside the network is useless. That single requirement puts them permanently in every internet-wide scan, and it means patching windows are measured against attackers who already know the box is there.

The pattern is the same one behind hypervisor escape bugs, where a component sitting between untrusted input and privileged execution earns disproportionate attention. Volume makes it worse. Vendors pushing hundreds of fixes in a single quarterly cycle leave defenders sorting priority out of noise before they can act on any of it.

What to do this week

Start with exposure rather than severity, then match what you find against the catalogue.

  • Identify every SonicWall SMA 1000 appliance in the estate and apply the vendor fixes for CVE-2026-83548 and CVE-2026-83549.
  • Patch Sangoma Switchvox for CVE-2026-9586 and CVE-2026-82329 together, since the observed attack chain uses both.
  • Assume compromise on anything that was unpatched and reachable. Look for reverse shells, unexpected outbound connections and unfamiliar processes before closing the ticket.
  • Restrict management interfaces to known source addresses. Most of these appliances have no reason to answer the whole internet.
  • Read the KEV feed directly rather than hearing about it a week later. Checking the catalogue yourself takes a few minutes and it is the same list federal agencies work from.

Federal civilian agencies get a binding remediation deadline when something lands in KEV. Everyone else gets the same list with no deadline attached, which is a fair description of why these numbers keep climbing.

What to watch

Whether the rate holds. One week of ten additions could be a disclosure artefact, with several vendors going public at once. Two or three consecutive weeks at this level would say something less comfortable about the distance between when exploitation starts and when anyone notices.

The biggest tech story, explained in 3 minutes every weekday. Choose your briefings →

Free. No spam. Unsubscribe in one click.

Enjoyed this? Get the briefing.

One email, every weekday: the top story, a useful tool, and what matters in tech - in under 3 minutes.

More from Future Technology

EVs

Audi's A2 E-tron Is the Affordable, Efficient EV the Market Has Been Asking For

EVs

CISA KEV, September 2026: Seven Exploited Flaws, and Attackers Are Hunting AI Servers

EVs

How to Check the CISA KEV Catalog and Find Out What Is Being Exploited Today

EVs

Magna Bets Big on Battery Swapping With an Extra 35 Million Dollars for Yuma Energy