On September 2, the US Cybersecurity and Infrastructure Security Agency (CISA) added seven known exploited vulnerabilities to its security catalog, warning federal agencies that flaws affecting products and several AI infrastructure tools are being exploited to deploy reverse shells, cryptocurrency miners, and steal credentials.
The additions show how quickly weaknesses in business software and AI platforms become attack routes. A PaperCut warning adds urgency, with two flaws combined with executing code without authentication.
Seven Flaws Move to the Front of the Patch Queue
The CISA known exploited vulnerabilities catalog now includes flaws affecting SonicWall SMA 1000 appliances, Sangoma Switchvox, JFrog Artifactory, Kludex Starlette, Kestra open-source software, and Berri LiteLLM. Their Common Vulnerability Scoring System ratings range from 6.5 to the maximum score of 10.0.
Attackers use compromised software to open reverse shells, steal credentials, deploy cryptocurrency miners, and penetrate the AI infrastructure across exposed enterprise systems.
Two SonicWall known exploited vulnerabilities can expose sensitive functions and allow an authenticated administrator to execute operating-system commands. Attackers have used Sangoma Switchvox and JFrog Artifactory flaws to create reverse shells, generate administrator tokens, and examine users, credentials, groups, and federated access.
The exploited vulnerabilities in Kestra and LiteLLM carry a wider concern because both products sit close to modern cloud and AI operations. Microsoft linked the Kestra weakness to an intrusion that established a reverse shell, inspected a Docker container environment, avoided defenses, collected data, and installed a cryptocurrency miner.
“The Kestra compromise exposed four impact paths: shell execution through the workflow engine, container-environment exposure through Docker socket access, host resource hijacking through miner deployment, and follow-on collection through workflow task execution,” according to Microsoft.
That activity makes each commonly exploited problem more than a routine defect when the service holds cloud credentials or connects to backend systems. Attackers can turn processing power into mining income while seeking longer access.
The CISA known exploited vulnerabilities include two weaknesses connected to LiteLLM. Malicious actors reportedly chained a Starlette flaw with another LiteLLM issue to bypass authentication, execute code, install an XMRig miner, modify SSH authorization files for persistence, and harvest model configurations, provider endpoints, API keys, and virtual keys.
These attacks blur the boundary between server intrusion and AI zero day exploits, as AI gateways provide another route to valuable credentials and computing resources. Security teams must protect AI workloads as control points, not isolated applications.
“Defenders should monitor AI workloads according to their control-plane role, not only as isolated applications,” said Microsoft as it summarized the pattern.
Federal civilian executive branch agencies were advised to patch most of the seven known exploited vulnerabilities by September 5, 2026. The Starlette and LiteLLM issues carry a September 16 deadline under Binding Operational Directive 26-04.
PaperCut Flaws Extend Enterprise Risk
PaperCut NG and MF provide another example of unknown vulnerability exploitation turning widely deployed administrative software into an entry point. Schools, government agencies, businesses, and managed service providers use the platforms for printers, authentication, quotas, and document workflows.
On August 31, CISA added CVE-2026-81578 and CVE-2026-82078 to the CISA known exploited vulnerabilities catalog.
The first permits an unauthenticated attacker to change critical configurations, while the second can execute arbitrary Java bytecode already present on the application classpath under the PaperCut server process.
When chained, the exploited vulnerabilities could support pre-authentication remote code execution. Internet-facing interfaces face particular danger because compromise may give attackers the permissions assigned to PaperCut.
US federal agencies have until September 14 to address the two CISA known exploited vulnerabilities. Although their connection to ransomware remains unknown, inclusion in the catalog confirms active exploitation and moves them ahead of flaws supported only by theoretical risk.
Organizations should identify exposed PaperCut servers, apply guidance, limit administrative access, and examine logs for unusual authentication events, configuration changes, or Java activity. The known exploited vulnerabilities may require isolation where mitigation is unavailable.
The widening list of known exploited vulnerabilities leaves defenders with shorter response windows and more infrastructure to inspect. It also highlights why patch decisions should follow evidence of attacks rather than scores alone.
As unknown vulnerability exploitation reaches print services, workflow engines, security appliances, and AI gateways, delayed remediation gives attackers time to convert one overlooked weakness into persistent access, stolen secrets, data collection, or illicit computing revenue.
Inside Telecom provides you with an extensive list of content covering all aspects of the tech industry. Keep an eye on our Cybersecurity sections to stay informed and up-to-date with our daily articles.