U.S. CISA adds BerriAI LiteLLM and Check Point Security Gateway flaws to its Known Exploited Vulnerabilities catalog
2026-06-09T08:51:43Z•416c4ca51a5098279c3e363776d98afa04ade78487a979460281ed3c5c025633
BerriAIC0XMOCISACheck PointEverest Forms ProIoT botnetKnown Exploited VulnerabilitiesLinux kernelNSO/WhatsAppUNC3753WordPressaccount takeoverdata breachnf_tables
What happened
Multiple high-impact incidents and vulnerabilities reported: CISA added BerriAI LiteLLM and a Check Point Security Gateway flaw (CVE-2026-42271) to its Known Exploited Vulnerabilities catalog. A Linux kernel nf_tables use-after-free (CVE-2026-23111) enables local privilege escalation to root. Everest Forms Pro for WordPress has a PHP injection/admin account creation flaw (CVE-2026-3300) actively exploited, and an IoT botnet variant (C0XMO) spreads via an old router overflow (CVE-2021-27137) to enable large-scale DDoS and competitor-killing behavior. Major breaches and campaigns include a 234GB
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 416c4ca51a5098279c3e363776d98afa04ade78487a979460281ed3c5c025633
- Enrichment time
- 2026-06-09T08:51:43Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.