Back to advisories

CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners

CISA added seven actively exploited vulnerabilities to the KEV catalog affecting SonicWall, Sangoma, JFrog, Kludex, Kestra, and Berri LiteLLM. Threat actors are chaining these flaws to deploy reverse shells, escalate privileges, and install crypto miners. Qilin ransomware operators have already weaponized at least one exploit chain.

CRITICALAdvisorySep 03, 2026
Action required
Immediately inventory and patch affected products. Prioritize SonicWall, Sangoma, and JFrog instances. Monitor for suspicious outbound connections (reverse shell indicators), new administrative accounts, and anomalous crypto miner process signatures.
Affected products
SMA 1000 AppliancesSonicWallSwitchvoxSangomaArtifactory