---
format: "aidr-story-markdown/v1"
id: "eba7ec75eb366cd8ba305436b1dd27044e0010d2bc69666e1bd56b54dde52469"
canonical_url: "https://aidr.today/eba7ec75?lang=en"
title: "CISA Adds 7 Vulnerabilities to KEV Catalog Including Artifactory Token Flaw"
lang: "en"
requested_lang: "en"
available_langs: ["en","vi"]
translation_fallback: null
fallback_fields: []
published_at: "2026-09-03T11:48:04.000Z"
category: "Infra"
topics: ["security","supply-chain","llm","infra"]
source_urls: ["https://huggingnews.com/cybersecurity/update-cisa-adds-7-vulnerabilities-to-kev-catalog-including-artifactory-4f797850","https://x.com/TheHackersNews/status/2095381541576904905"]
summary: "The Cybersecurity and Infrastructure Security Agency designated a group of seven newly weaponized software flaws as urgent security risks on September 3. These vulnerabilities allow threat actors to deploy reverse shells and cryptocurrency miners across networks utilizing LiteLLM and Switchvox while harvesting API keys. The JFrog Artifactory vulnerability features an authentication bypass in default configurations that grants unauthenticated users with network access administrative privileges through the minting of administrator tokens. Because the tool manages container images and AI model artifacts, a successful breach potentially allows attackers to manipulate the software supply chain before code reaches production."
---

# CISA Adds 7 Vulnerabilities to KEV Catalog Including Artifactory Token Flaw

> [Open the canonical story](<https://aidr.today/eba7ec75?lang=en>)

**Published:** 2026-09-03T11:48:04.000Z
**Category:** Infra
**Topics:** security, supply\-chain, llm, infra

## Summary

The Cybersecurity and Infrastructure Security Agency designated a group of seven newly weaponized software flaws as urgent security risks on September 3\. These vulnerabilities allow threat actors to deploy reverse shells and cryptocurrency miners across networks utilizing LiteLLM and Switchvox while harvesting API keys\. The JFrog Artifactory vulnerability features an authentication bypass in default configurations that grants unauthenticated users with network access administrative privileges through the minting of administrator tokens\. Because the tool manages container images and AI model artifacts, a successful breach potentially allows attackers to manipulate the software supply chain before code reaches production\.

## Sources

- [Story source](<https://huggingnews.com/cybersecurity/update-cisa-adds-7-vulnerabilities-to-kev-catalog-including-artifactory-4f797850>)
- [Story source](<https://x.com/TheHackersNews/status/2095381541576904905>)

