SECURITYTHE HACKER NEWS
LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE
CISA added a high-severity command injection vulnerability (CVE-2026-42271) in BerriAI LiteLLM to its KEV catalog due to active exploitation. The flaw allows authenticated users to execute arbitrary commands on affected systems.
Mentioned
Related Signal
Adjacent reporting
- New PHP Composer Flaws Enable Arbitrary Command Execution — Patches Released
- Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV
- Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active Exploitation
- Apache ActiveMQ CVE-2026-34197 Added to CISA KEV Amid Active Exploitation
- CISA Adds Actively Exploited Linux Root Access Bug CVE-2026-31431 to KEV
- LiteLLM CVE-2026-42208 SQL Injection Exploited within 36 Hours of Disclosure