Skip to content

Data collected

CVEs Live

Added to CISA KEV, 31 Aug 2026 to 6 Sep 2026

10 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog in this week. Listed by risk: highest EPSS first.

Build snapshot collected · KEV catalog 2026.10.02 · EPSS of 2 Oct 2026 · not a live feed: collected once, at build time

  1. CVE-2026-81578Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    PaperCut · NG/MF

    PaperCut NG/MF Missing Authentication for Critical Function Vulnerability

    Severity

    8.8HIGHCVSS 4.0 · eb41dac7-0af8-4f84-9f6d-0272772514f4

    Attack probability (EPSS)

    85.2%99.7th pct

    KEV dates

    added due
  2. CVE-2026-82078Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    PaperCut · NG/MF

    PaperCut NG/MF Unsafe Reflection Vulnerability

    Severity

    9.4CRITICALCVSS 4.0 · eb41dac7-0af8-4f84-9f6d-0272772514f4

    Attack probability (EPSS)

    61.4%99.1th pct

    KEV dates

    added due
  3. CVE-2026-85046Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Google · Chromium V8

    Google Chromium V8 Type Confusion Vulnerability

    Severity

    8.8HIGHCVSS 3.1 · CISA-ADP

    Attack probability (EPSS)

    48.9%99th pct

    KEV dates

    added due
  4. CVE-2026-9586Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Sangoma · Switchvox

    Sangoma Switchvox SQL Injection Vulnerability

    Severity

    9.3CRITICALCVSS 4.0 · 57dba5dd-1a03-47f6-8b36-e84e47d335d8

    Attack probability (EPSS)

    19.0%97th pct

    KEV dates

    added due
  5. CVE-2026-82329Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    JFrog · Artifactory

    JFrog Artifactory Improper Authentication Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · jfrog.com

    Attack probability (EPSS)

    14.1%96th pct

    KEV dates

    added due
  6. CVE-2026-83549Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    SonicWall · SMA1000 Appliances

    SonicWall SMA1000 Appliances OS Command Injection Vulnerability

    Severity

    7.8HIGHCVSS 3.1 · CISA-ADP

    Attack probability (EPSS)

    10.8%96th pct

    KEV dates

    added due
  7. CVE-2026-83548Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    SonicWall · SMA1000 Appliances

    SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

    Severity

    10.0CRITICALCVSS 3.1 · CISA-ADP

    Attack probability (EPSS)

    8.76%95th pct

    KEV dates

    added due
  8. CVE-2026-48710Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Kludex · Starlette

    Kludex Starlette HTTP Request/Response Smuggling Vulnerability

    Severity

    6.5MEDIUMCVSS 3.1 · NVD

    Attack probability (EPSS)

    7.06%94th pct

    KEV dates

    added due
  9. CVE-2026-49869Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Kestra · Kestra OSS

    Kestra OSS OS Command Injection Vulnerability

    Severity

    10.0CRITICALCVSS 3.1 · github.com

    Attack probability (EPSS)

    2.10%81th pct

    KEV dates

    added due
  10. CVE-2026-59822Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    BerriAI · LiteLLM

    BerriAI LiteLLM Improper Authentication Vulnerability

    Severity

    8.8HIGHCVSS 4.0 · github.com

    Attack probability (EPSS)

    0.84%56th pct

    KEV dates

    added due

All entries are in KEV, so the order is EPSS probability, then published CVSS. Scores are shown as each source published them.

The week in numbers

8 vendors had products added: PaperCut (2), SonicWall (2), Google (1), Sangoma (1), JFrog (1), Kludex (1), Kestra (1), BerriAI (1). CISA marks none of the 10 as known to be used in ransomware campaigns.

Due dates in this batch run from 5 Sep 2026 to 18 Sep 2026. They bind US federal civilian agencies; for everyone else they indicate how urgent CISA considers each fix.

Other weeks

Questions

How many vulnerabilities were added to CISA KEV in the week of 31 Aug 2026?

10, between 31 Aug 2026 and 6 Sep 2026, according to catalog version 2026.10.02 collected on 3 Oct 2026.

Why do additions come in batches?

CISA updates the catalog on US business days and often adds several CVEs in one notice, for example a set of vulnerabilities in the same product that are chained in an attack. Weeks with no additions also happen.

How is the week defined?

By the "dateAdded" field of each entry, grouped in ISO 8601 weeks, Monday to Sunday.

Related sections