# CISA Adds Exploited LiteLLM, Artifactory and Switchvox Bugs to High‑Risk List as Attacks Hit AI and Dev Tools

*Thursday, September 3, 2026 at 6:17 AM UTC — Hamer Intelligence Services Desk*

**Published**: 2026-09-03T06:17:57.279Z (1h ago)
**Category**: cyber | **Region**: Global
**Importance**: 8/10
**Sources**: OSINT
**Permalink**: https://hamerintel.com/data/articles/16689.md
**Source**: https://hamerintel.com/summaries

---

**Deck**: Attackers are exploiting flaws in LiteLLM, Artifactory and Switchvox to deploy crypto‑miners, create unauthorized admin tokens and harvest API keys, prompting U.S. cyber authorities to add seven vulnerabilities to a catalog that flags exploited bugs federal agencies must urgently address.

Active attacks on specialist developer and communications tools are turning internal AI and software infrastructure into prime entry points for intruders.

Security researchers and U.S. cyber authorities report that attackers are exploiting vulnerabilities in LiteLLM, Artifactory and Switchvox. The flaws let intruders deploy cryptocurrency miners and reverse shells, mint unauthorized administrator tokens, and harvest API keys that can be used to move deeper into corporate and government networks.

In response, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added seven exploited vulnerabilities tied to these products to its Known Exploited Vulnerabilities catalog. The list is used to signal that certain bugs are being used in real‑world attacks and that fixing them is an urgent task, particularly for federal agencies.

LiteLLM helps route and manage large language model requests inside organizations, often sitting in the middle of internal AI deployments that handle sensitive data. Artifactory underpins software development by storing and managing code components, while Switchvox provides business telephony and unified communications. If attackers gain control of any one of these systems, they can move from what looks like a peripheral service to a position with access to source code, call records or AI‑processed information.

For development and IT teams, the immediate impact is the need to locate vulnerable instances, apply patches and review logs for signs of compromise. The broader risk is that intruders use stolen API keys and admin tokens to alter code artifacts, plant backdoors or siphon off proprietary data, sometimes long before unusual resource usage from a crypto‑miner is noticed.

Software supply chains are a particular concern. Artifactory repositories often feed directly into production builds, so a compromise there can lead to malicious code being inserted into applications that then reach customers or run inside sensitive environments.

The exploitation of LiteLLM instances highlights a newer kind of exposure. As organizations rapidly adopt generative AI, internal gateways and routing tools may not be protected by the same mature processes that guard databases or payment systems. A vulnerable AI gateway that sits between employees and powerful language models can reveal prompts, output and, in some setups, the underlying business data being processed.

CISA’s move to spotlight these flaws underlines that once tools handle real customer data, internal communications or code, their vulnerabilities can carry wide consequences, especially when exploited in government networks and among contractors that support critical sectors.

Key developments to watch include any emergency patch directives for U.S. federal agencies, vendor disclosures about whether customer environments were affected, and reports of downstream effects tied to Artifactory breaches. If criminal or state‑linked groups are seen combining these vulnerabilities with others to reach high‑value targets, pressure on organizations to harden their internal tooling is likely to increase.
