← All Cyber Watch editions

Small Business Cyber Watch · September 3, 2026

Small Business Cyber Watch — September 3, 2026

Practical context and recommended next steps for business leaders.

September 3, 2026 — Small Business Cyber Watch

Today’s priority: Review the newest entries in CISA’s authoritative catalog of vulnerabilities known to be exploited in the wild. The most recent catalog additions shown below are dated September 2, 2026.

BerriAI LiteLLM: BerriAI LiteLLM Improper Authentication Vulnerability

CVE-2026-59822 · Added by CISA September 2, 2026

What changed: BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.

Why it matters: CISA includes vulnerabilities in this catalog when there is evidence they are being actively exploited. An affected internet-facing or business-critical system deserves prompt attention.

What to do: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. CISA remediation target: September 16, 2026.

Kludex Starlette: Kludex Starlette HTTP Request/Response Smuggling Vulnerability

CVE-2026-48710 · Added by CISA September 2, 2026

What changed: Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271.

Why it matters: CISA includes vulnerabilities in this catalog when there is evidence they are being actively exploited. An affected internet-facing or business-critical system deserves prompt attention.

What to do: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. CISA remediation target: September 16, 2026.

Kestra Kestra OSS: Kestra OSS OS Command Injection Vulnerability

CVE-2026-49869 · Added by CISA September 2, 2026

What changed: Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.

Why it matters: CISA includes vulnerabilities in this catalog when there is evidence they are being actively exploited. An affected internet-facing or business-critical system deserves prompt attention.

What to do: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. CISA remediation target: September 5, 2026.

JFrog Artifactory: JFrog Artifactory Improper Authentication Vulnerability

CVE-2026-82329 · Added by CISA September 2, 2026

What changed: JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges.

Why it matters: CISA includes vulnerabilities in this catalog when there is evidence they are being actively exploited. An affected internet-facing or business-critical system deserves prompt attention.

What to do: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. CISA remediation target: September 5, 2026.

Sangoma Switchvox: Sangoma Switchvox SQL Injection Vulnerability

CVE-2026-9586 · Added by CISA September 2, 2026

What changed: Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.

Why it matters: CISA includes vulnerabilities in this catalog when there is evidence they are being actively exploited. An affected internet-facing or business-critical system deserves prompt attention.

What to do: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. CISA remediation target: September 5, 2026.

Small-business action list

  • Ask your IT provider whether any affected product is in your environment.
  • Prioritize internet-facing, remote-access, identity, and backup systems.
  • Apply vendor updates or mitigations after appropriate testing.
  • Review privileged-account activity and confirm recoverable backups.

Verified source: CISA Known Exploited Vulnerabilities Catalog.

This edition is prepared automatically from CISA’s published data and provides general awareness, not an assessment of any specific organization.

AI + IT, under one roof

Build what is next.
Protect what matters.

Talk to ProTeamMSP