we_are_coded.by CODE · The world, decoded
БГ
CISA

Seven flaws in one day in the actively exploited catalogue, LiteLLM and Artifactory among them

CISA · event date: 2 September 2026Security

On 2 September CISA added seven CVEs to KEV. For people running AI infrastructure, two stand out: LiteLLM lets anyone with a made-up token reach the MCP tools, and Artifactory hands out admin rights without a login. The deadline for Artifactory and SonicWall is 5 September.

In short
  • CVE-2026-59822 in LiteLLM: the MCP endpoint can accept an arbitrary Bearer token; fixed in 1.84.0, and meanwhile /mcp/ can be blocked.
  • CVE-2026-82329 in JFrog Artifactory: under default configuration an attacker without a login becomes admin; cloud is protected, self-hosted servers must update.
  • Also: SonicWall SMA1000 (CVE-2026-83548 with CVSS 10.0 and CVE-2026-83549), Starlette, Kestra and Sangoma Switchvox.
Checked on1 October 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

A made-up token. Literally any string after the word Bearer, and a vulnerable LiteLLM can let you through to the tools you have wired to your agents.

LiteLLM is the gateway teams use to route requests to different models. If MCP tools hang off it - a database, email, an internal API - an attacker can list them and call them.

The facts: on 2 September 2026 CISA added seven vulnerabilities with confirmed exploitation to the Known Exploited Vulnerabilities catalogue. CVE-2026-59822 in BerriAI LiteLLM: the MCP Streamable HTTP endpoint can accept an arbitrary Bearer token and give an unauthenticated attacker a session with which they list and call the configured MCP tools; per the project's advisory (GHSA-7488-6r32-c95q, CVSS 4.0: 8.8), versions before 1.84.0 are affected, and the workaround is to disable MCP routes or block /mcp/ at the reverse proxy; deadline 16 September. CVE-2026-82329 in JFrog Artifactory: under default configuration an unauthenticated attacker with network access can obtain administrative privileges; JFrog rates it critical and published it on 28 August, cloud instances are already protected, and for self-hosted servers fixes are per branch, from 7.111.21 to 7.161.20; deadline 5 September. CVE-2026-83548 and CVE-2026-83549 in SonicWall SMA1000: an unauthenticated SSRF (CVSS 10.0) and command injection after login as administrator (CVSS 7.8); SonicWall's advisory of 1 September describes a case of active exploitation; deadline 5 September. Also: CVE-2026-48710 in Starlette (HTTP request smuggling that can lead to authentication bypass), CVE-2026-49869 in Kestra OSS (command injection without login) and CVE-2026-9586 in Sangoma Switchvox (SQL injection without login).

Artifactory, again, and again without confusing things

The name enters KEV for the second time in a week. On 27 August it was a milder flaw that needs a login. This one is from the other end: no login, default configuration, straight to admin. JFrog published it on 28 August, and CISA gives three days.

Artifactory was also the stage of the incident OpenAI described on 26 August. Neither JFrog nor CISA links this CVE to it, and we will not either. What they share is something else: the internal package server turned out to be a far more interesting target than the network diagrams say.

An internal package server is not internal if the network can see it.

If your network has LiteLLM with MCP tools attached, update to 1.84.0 or close /mcp/ tonight. Self-hosted Artifactory gets updated to the version for your branch. For SonicWall SMA1000: the latest hotfix and a conversation with their support about traces of compromise, because that is what their advisory says.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→CISA - Known Exploited Vulnerabilities Catalog→BerriAI/litellm - GHSA-7488-6r32-c95q: MCP Authentication Bypass via OAuth2 Passthrough Fallback→JFrog - Security Advisories→SonicWall PSIRT - SNWLID-2026-0016, 01.09.2026
Original: https://wearecoded.com/en/articles/cisa-kev-litellm-artifactory-sonicwall-0902.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news