# Exploited LiteLLM, Artifactory and Switchvox flaws added to CISA’s high‑priority vulnerability list

*Thursday, September 3, 2026 at 6:20 AM UTC — Hamer Intelligence Services Desk*

**Published**: 2026-09-03T06:20:00.843Z (1h ago)
**Category**: cyber | **Region**: Global
**Importance**: 7/10
**Sources**: OSINT
**Permalink**: https://hamerintel.com/data/articles/16697.md
**Source**: https://hamerintel.com/summaries

---

**Deck**: Attackers are exploiting vulnerabilities in LiteLLM, Artifactory and Switchvox to deploy crypto miners, open reverse shells, mint admin tokens and steal API keys, prompting U.S. cybersecurity officials to add seven bugs to a list of known exploited flaws.

Recent cyberattacks on everyday developer and communications tools have pushed U.S. authorities to elevate several software flaws to top‑priority status.

Security researchers report that attackers are chaining together vulnerabilities in LiteLLM, Artifactory and Switchvox to gain deep access to corporate systems. The intruders are using these weaknesses to deploy cryptocurrency miners and reverse shells, generate administrative tokens and harvest API keys.

In response, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added seven exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. Inclusion in the KEV list effectively tells federal agencies to treat these bugs as urgent patching priorities, reflecting evidence of real‑world compromise rather than hypothetical risk.

The techniques involved underscore why these systems are attractive targets. Crypto miners can quietly siphon computing power and electricity. Reverse shells give attackers an interactive foothold inside networks, letting them move laterally or steal data. Stolen API keys can unlock access to cloud services and other connected systems that go well beyond the originally affected server.

LiteLLM connects applications to large language models, so a breach could expose prompts, training data or user inputs. Artifactory sits inside software build pipelines, hosting code packages and artifacts, while Switchvox provides business telephony. Weaknesses in any of these tools can therefore become entry points into wider environments.

Signals to watch include how quickly organizations patch or mitigate the listed vulnerabilities, whether more victims report intrusions tied to these flaws, and if vendors update guidance or configurations for affected products.
