Skip to content
The Nexus
DossierENTITY

command injection vulnerability

Coverage of command injection vulnerability in the Nexus archive.

Earliest in view: Jun 9 · 06:26 UTCMost recent: Jul 27 · 22:49 UTC
Co-mentioned in this coverage
Recent coverage
  • SECURITYJul 27 · 22:49 UTCBLEEPING COMPUTER
    Arista patches VeloCloud Orchestrator zero-day exploited in attacks

    Arista has released a patch for a maximum-severity command injection vulnerability in its on-premises VeloCloud Orchestrator deployments, which is currently being exploited in cyber attacks. The vulnerability, classified as a zero-day, allows attackers to execute arbitrary commands, prompting urgent remediation actions.

  • SECURITYJun 9 · 06:26 UTCTHE HACKER NEWS
    LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE

    CISA added a high-severity command injection vulnerability (CVE-2026-42271) in BerriAI LiteLLM to its KEV catalog due to active exploitation. The flaw allows authenticated users to execute arbitrary commands on affected systems.

command injection vulnerability · Dossier · The Nexus