CISA flags seven actively exploited security flaws


CISA added seven actively exploited CVEs to its Known Exploited Vulnerabilities catalog on September 2. The list includes SonicWall SMA1000 SSRF and command injection flaws (CVE-2026-83548, CVE-2026-83549), plus a JFrog Artifactory authentication bypass (CVE-2026-82329). Active exploitation means public PoC code or automated scanners are already deployed. Federal agencies have BOD 26-04 remediation deadlines; everyone else running SMA1000 VPN gateways or Artifactory instances should patch immediately.

Elsewhere, CERN is migrating 2,200+ accelerator-control systems from RHEL to Debian 13 after RHEL's x86-64-v2 baseline dropped support for pre-2008 CPUs still running industrial hardware.

In this issue:

  • CISA KEV catalog: seven actively exploited CVEs including SonicWall and JFrog flaws
  • AVX-512 xor_gen() patches v5 for Linux: RAID 5/6 gains on Ryzen 9 9950X
  • CERN migrating 2,200 control systems to Debian 13 after RHEL drops x86-64-v1 support
  • Google open-sources Mantis vulnerability scanner with 85% token reduction via hierarchical summaries

CISA flags seven actively exploited vulnerabilities

The Signal CISA added seven actively exploited CVEs to its KEV catalog on September 2, 2026.

What Changed

  • CVE-2026-83548 and CVE-2026-83549: SonicWall SMA1000 SSRF and command injection flaws.
  • CVE-2026-82329: JFrog Artifactory authentication bypass under active exploitation.
  • CVE-2026-9586: Sangoma Switchvox SQL injection vulnerability added to KEV.
  • Four additional CVEs in Kludex Starlette, Kestra OSS, and BerriAI LiteLLM.
  • BOD 26-04 requires federal agencies to remediate high-risk KEV vulnerabilities on publicly exposed assets.

Operational Impact SMA1000 appliances function as enterprise VPN gateways; exploitation grants full appliance control. The JFrog Artifactory bypass creates supply chain risk by allowing unauthorized access to artifact repositories that feed build pipelines. Federal agencies must remediate KEV vulnerabilities on exposed assets and assess pre-patch compromise per BOD 26-04 timelines.

Watch For Active exploitation means public proof-of-concept code or automated scanning is already deployed. Patch SMA1000 and Artifactory instances immediately if publicly exposed.


AVX-512 xor_gen Patches Promise Major RAID Gains on Zen 5

The Signal

Eric Biggers posted v5 of AVX-512 xor_gen() patches for Linux, showing major RAID 5/6 parity performance gains on Ryzen 9 9950X.

What Changed

  • Consolidates kernel CPU feature flag handling for AVX/AVX-512 and XCR0 xstate checks.
  • Adds AVX-512 optimized xor_gen() for RAID parity generation and validation operations.
  • Fixes cpu_has_xfeatures() confusion, adds UML support for feature detection.
  • Benchmarks show substantial gains for 4-8 disk RAID arrays on AMD Zen 5 hardware.
  • Patches target Linux 7.4 merge window after missing 7.3 cycle. https://www.phoronix.com/news/AVX-512-xor-gen-v5

Operational Impact

Teams running software RAID 5 or RAID 6 on Zen 5 systems will see measurable throughput improvements for parity operations once this lands. The XCR0 xstate consolidation also fixes cases where hypervisors don't enable required xstate features, preventing AVX-512 detection failures. Future Intel platforms with AVX-512 will benefit from the same optimizations.

Watch For

Linux 7.4 merge window later this year. The patch series now addresses the CPU feature detection issues that delayed earlier versions.


CERN Migrates 2,200 Industrial Control Systems from RHEL to Debian

The Signal CERN is migrating 2,200+ industrial accelerator-control computers to Debian 13 by end-2026 after a decade on CentOS/RHEL.

What Changed

  • RHEL's x86-64-v2 compiler baseline excludes pre-2008 CPUs lacking SSSE3/SSE4.1 instructions.
  • Migration targets Debian 13 for industrial embedded systems, not data center infrastructure.
  • CERN cited lack of standard tooling for automated package building and publishing.
  • Multi-version package support gaps complicate dependency management for legacy control systems.
  • CentOS Stream evaluated but rejected before choosing Debian. https://www.phoronix.com/news/CERN-Goes-Debian-Leaving-RHEL

Operational Impact The x86-64-v2 baseline matters for facilities running decade-old industrial hardware that can't justify replacement. Core 2 Duo and earlier Opteron systems lose compiler support. Research institutions and industrial control environments face similar decisions: pay for extended RHEL lifecycle support, accept hardware replacement costs, or migrate to distributions maintaining broader architecture support. CERN's tooling gaps—especially around automated package pipelines—signal that Debian's enterprise tooling still lags behind RHEL-native workflows.

Watch For Debian 13 release schedule and whether CERN contributes upstream tooling improvements for multi-version package management. Other CERN computing infrastructure remains on RHEL/AlmaLinux.


Google Releases Mantis Open-Source Vulnerability Scanner

The Signal

Google open-sourced Mantis, an agentic framework for automated vulnerability discovery, triage, reproduction, and patching.

What Changed

  • Mantis addresses AI code scanner hallucinations; industry true-positive rates under 7%.
  • Constructs hierarchical security summary trees, reducing token overhead by 85%.
  • Combines critic/review agents with sandboxed reproduction to ground vulnerability findings.
  • Auto-generates architectural and threat model docs from repository commit history.
  • Available now on GitHub at https://github.com/google/mantis

Operational Impact

Teams running AI-assisted security scanning can now deploy a framework designed to filter false positives before human review. The hierarchical summarization condenses files into directory and root-level summaries, preserving structural context across large repositories. You'll need a cyber sandbox with clear vulnerability reproduction criteria to get meaningful results. Google recommends feeding human-curated context (threat models, vulnerability acceptance policies) alongside the automated analysis.

Watch For

The `mantis-advise` skill extends beyond vulnerability hunting into codebase understanding and technical debt analysis. Expect broader adoption for onboarding engineers to unfamiliar repositories and documenting legacy systems.


Quick Reads

  • CISA — Added seven actively exploited CVEs including SonicWall and JFrog flaws to KEV catalog.
  • Linux Kernel — AVX-512 patches deliver major RAID parity performance gains on AMD Zen 5 processors.
  • CERN — Migrating 2,200+ industrial control systems from RHEL to Debian 13 by year-end.
  • Google — Released Mantis open-source framework for AI-powered vulnerability discovery and automated patching.

Subscribe to Signal Field

Data & infrastructure news. Subscribers get new posts by email a day before they go live on the site.

Email signup is coming soon — in the meantime, follow the Signal Field RSS feed.

Need a Custom MCP System?

Configuration & integration for your stack — from tool selection to production deployment. The directory recommends. The consultancy configures.

Get Started →