U.S. CISA adds BerriAI LiteLLM and Check Point Security Gateway flaws to its Known Exploited Vulnerabilities catalog

2026-06-09T08:51:43Z416c4ca51a5098279c3e363776d98afa04ade78487a979460281ed3c5c025633
BerriAIC0XMOCISACheck PointEverest Forms ProIoT botnetKnown Exploited VulnerabilitiesLinux kernelNSO/WhatsAppUNC3753WordPressaccount takeoverdata breachnf_tables

What happened

Multiple high-impact incidents and vulnerabilities reported: CISA added BerriAI LiteLLM and a Check Point Security Gateway flaw (CVE-2026-42271) to its Known Exploited Vulnerabilities catalog. A Linux kernel nf_tables use-after-free (CVE-2026-23111) enables local privilege escalation to root. Everest Forms Pro for WordPress has a PHP injection/admin account creation flaw (CVE-2026-3300) actively exploited, and an IoT botnet variant (C0XMO) spreads via an old router overflow (CVE-2021-27137) to enable large-scale DDoS and competitor-killing behavior. Major breaches and campaigns include a 234GB

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
416c4ca51a5098279c3e363776d98afa04ade78487a979460281ed3c5c025633
Enrichment time
2026-06-09T08:51:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · U.S. CISA adds BerriAI LiteLLM and Check Point Security Gateway flaws to its Known Exploited Vulnerabilities catalog · Baitaphish