Dossier
command injection vulnerability
Coverage of command injection vulnerability in the Nexus archive.
- Arista patches VeloCloud Orchestrator zero-day exploited in attacks
Arista has released a patch for a maximum-severity command injection vulnerability in its on-premises VeloCloud Orchestrator deployments, which is currently being exploited in cyber attacks. The vulnerability, classified as a zero-day, allows attackers to execute arbitrary commands, prompting urgent remediation actions.
- LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE
CISA added a high-severity command injection vulnerability (CVE-2026-42271) in BerriAI LiteLLM to its KEV catalog due to active exploitation. The flaw allows authenticated users to execute arbitrary commands on affected systems.