The federal government's list of vulnerabilities under active attack grew by seven this week.
CISA added seven vulnerabilities to its Known Exploited Vulnerabilities catalog, all confirmed to be under active exploitation. The list spans a SQL injection flaw in Sangoma's Switchvox phone system, a request-smuggling bug in the Starlette web framework, an OS command-injection issue in the Kestra orchestration tool, an authentication flaw in BerriAI's LiteLLM proxy, another authentication bug in JFrog's Artifactory, and two separate SonicWall SMA1000 flaws (a server-side request forgery and an OS command-injection bug) hitting the company's remote-access appliances. That's six products in total, with SonicWall accounting for two of the seven CVEs. CISA did not disclose who is behind the exploitation or how widely it has spread.
Federal civilian agencies now have a clock running. Binding Operational Directive 26-04 requires them to prioritize patching KEV-listed flaws that hand attackers full control of an asset, and to check whether intruders already got in before the fix existed. With thousands of CVEs published every year, the catalog has become the closest thing most IT teams have to a real-time triage list.
None of this is exotic, just the usual mix of web apps, remote-access gear, and dev tooling that keeps landing on this list: a reminder that patching discipline still beats novelty when it comes to actual breaches.