AI gateways are becoming high-value attack surfaces.
CISA added seven actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on Sept. 2, including flaws in LiteLLM, Kestra, and Starlette. The remaining entries affect JFrog Artifactory, Sangoma Switchvox, and SonicWall SMA1000 appliances, putting AI, DevOps, communications, and remote-access infrastructure on security teams’ patch lists.
The additions follow attacks targeting LiteLLM and MCP servers involving credential theft, command execution, and cryptomining. Microsoft and Wiz have also documented attacks against exposed AI gateways and workflow platforms, where compromise can expose credentials, execution privileges, and connected enterprise services.
Exploited flaws reach AI gateways and enterprise infrastructure
CISA’s Sept. 2 KEV additions include:
- CVE-2026-59822: BerriAI LiteLLM improper authentication
- CVE-2026-49869: Kestra OS command injection
- CVE-2026-82329: JFrog Artifactory improper authentication
- CVE-2026-48710: Starlette HTTP request/response smuggling
- CVE-2026-9586: Sangoma Switchvox SQL injection
- CVE-2026-83548: SonicWall SMA1000 server-side request forgery
- CVE-2026-83549: SonicWall SMA1000 OS command injection
LiteLLM’s CVE-2026-59822 can allow an unauthenticated attacker using a fabricated Bearer token to establish an authenticated MCP session and potentially reach configured tools. The flaw affects versions before 1.84.0 and is fixed in 1.84.0, according to the LiteLLM security advisory.
Microsoft documented compromises involving LiteLLM, RAGFlow, and Kestra on Aug. 26, including credential harvesting, persistence, reverse shells, and cryptomining. A day later, Wiz reported sustained attacks across 90 days of AI-infrastructure honeypot telemetry, including activity against LiteLLM and exposed MCP services.
The activity extends to AI coding tools, MCP servers, and developer infrastructure, which can hold source code access, credentials, and CI/CD permissions.
CISA has not attributed the seven Sept. 2 entries to one threat actor or coordinated campaign.
Federal deadlines put patching on a short clock
CISA set Sept. 5 remediation deadlines for the two SonicWall flaws and the Switchvox, Artifactory, and Kestra vulnerabilities on qualifying federal systems. LiteLLM and Starlette are due Sept. 16.
Both SonicWall flaws have been confirmed under active exploitation. CVE-2026-83548 is a pre-authentication SSRF vulnerability rated CVSS 10.0, while CVE-2026-83549 can enable OS command execution by an authenticated administrator. On Sept. 4, Singapore’s Cyber Security Agency urged affected organizations to update immediately, adding to concerns following another round of actively exploited SMA1000 zero-days.
Organizations should:
- Patch or mitigate affected versions immediately and verify dependent systems for vulnerable components.
- Reduce internet exposure for AI gateways, MCP endpoints, orchestration platforms, and management interfaces.
- Restrict privileged and MCP access with least-privilege accounts and tightly scoped tool permissions.
- Rotate potentially exposed credentials including API keys, cloud credentials, service tokens, and administrator secrets.
- Segment AI and orchestration systems from databases, CI/CD platforms, and cloud control planes.
- Hunt for prior exploitation including suspicious authentication, commands, reverse shells, credential access, and cryptomining.
- Test incident response plans for containment, credential rotation, forensic logging, escalation, and recovery.
For compromised SMA1000 appliances, SonicWall recommends checking for indicators of compromise and, when necessary, re-imaging or redeploying systems and resetting user and administrator passwords and TOTP tokens.
Read more: Recent real-world intrusions show how attackers are using AI for reconnaissance, credential theft, and post-compromise activity.





