CISA Flags Seven Actively Exploited Vulnerabilities Businesses Should Patch Now
The US Cybersecurity and Infrastructure Security Agency (CISA) has added seven new security flaws to its Known Exploited Vulnerabilities (KEV) Catalog, confirming that attackers are actively exploiting them in the wild. The affected products include Sangoma Switchvox, Kludex Starlette, Kestra OSS, BerriAI LiteLLM, and JFrog Artifactory - tools used across business communications, software development, and IT infrastructure management.
These vulnerabilities range from SQL injection and command injection flaws to authentication bypass and request-smuggling issues, all of which can allow attackers to gain unauthorised access, manipulate systems, or steal sensitive data. Because CISA only adds vulnerabilities to this catalog once there is confirmed evidence of real-world exploitation, their inclusion signals genuine, ongoing risk rather than theoretical concern.
Australian small and medium businesses that use any of these products - directly or through third-party vendors and developers - should check whether they are running affected versions and apply available patches immediately. Even businesses that don't directly manage these platforms may be exposed if their IT providers or software supply chain relies on them.