Skip to content
feed: live
>_0dayNews
cisa kev
● Breaking

CISA Adds Seven Exploited Flaws to KEV Catalog

CISA added seven actively exploited vulnerabilities to KEV on September 3, including a critical Sangoma Switchvox SQL injection. Federal agencies face BOD 26-04 remediation deadlines.

CISA Adds Seven Exploited Flaws to KEV Catalog
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
fuseMarisol "Fuse" Delgado·Published ·2 min read

CISA added seven vulnerabilities to its Known Exploited Vulnerabilities catalog on September 3, confirming active exploitation across multiple products. Confirmed among the additions: CVE-2026-9586, the unauthenticated SQL injection in Sangoma Switchvox (CVSS 9.8, critical) that attackers have been using to deploy reverse shells against enterprise VoIP infrastructure.

Federal civilian agencies operating under Binding Operational Directive 26-04 have mandatory remediation deadlines for all entries. The full seven-item batch is on the KEV catalog page.

CVE-2026-9586: Switchvox SQL injection, reverse shells confirmed

Switchvox’s SQL injection flaw lets unauthenticated attackers run arbitrary SQL against the backend PostgreSQL database. From there, the path to remote code execution is a single step. Sangoma patched the issue in Switchvox 8.4.0.2. Anything older is exposed.

The CISA catalog entry aligns with exploitation reports from earlier this week via The Hacker News: attackers are deploying reverse shells on compromised Switchvox systems, establishing persistent access rather than just scanning. This is a confirmed post-exploitation behavior, not a theoretical risk.

The CVE-2026-9586 entry has full technical details and the Sangoma advisory link.

What the catalog addition means

KEV additions do not mean exploitation is possible. They mean exploitation is happening. That is a different operational question, and it has a different answer for patch scheduling: this is a fire drill, not a maintenance window.

The catalog now reflects active attack surface as CISA sees it. For the seven flaws added today, the window to patch before attackers reach your environment is narrow or already closed on vulnerable systems facing the internet.

September has been a heavy month for active exploitation. SonicWall SMA1000’s chained zero-days CVE-2026-83548 and CVE-2026-83549 are under active attack. JFrog Artifactory CVE-2026-82329 was exploited within days of disclosure. Langflow CVE-2026-0768 is being used for cloud credential theft. The pace is not slowing.

Patch priority

For CVE-2026-9586: update Sangoma Switchvox to 8.4.0.2 or later. Check the full KEV catalog for the other six flaws in this batch and cross-reference against your asset inventory. If the EPSS scoring methodology is part of your patch prioritization workflow, KEV status overrides EPSS for any given flaw: confirmed exploitation is a harder signal than exploitation probability.

Background on what KEV additions mean for your patching process if you need the broader context.

Related CVEs
  • [ HIGH ]CVE-2026-9586Sangoma Switchvox SQL Injection Vulnerability

Found this useful? Share it.