CVE Tools

CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners

The Hacker NewsBy The Hacker News

Reported exploitedSonicWall SMA 1000QilinSangoma Switchvox

Our summary

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added seven vulnerabilities to its Known Exploited Vulnerabilities catalog after confirming active real-world attacks. Among the critical additions are CVE-2026-83548 and CVE-2026-83549 in SonicWall SMA 1000 Appliances, alongside CVE-2026-82329 in JFrog Artifactory and CVE-2026-9586 in Sangoma Switchvox. Microsoft and other researchers report that threat actors are leveraging these flaws to deploy reverse shells and cryptocurrency miners, with particular focus on AI infrastructure components like Kestra OSS and LiteLLM.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store