CVE-2026-42208: LiteLLM bug exploited 36 hours after its disclosure

2026-04-30T02:51:46Z84258ba5f372fad5664e5e7f563479218cc902506997f842c5834bbb25397590
AnodotCISAGitHubKnown Exploited VulnerabilitiesLiteLLMMicrosoft Entra IDMorpheus spywareSQL injectionShinyHuntersSilentGlassauthentication bypasscPaneldata breachinternet censorshipphishingprivilege escalationremote code execution

What happened

Multiple high‑risk security incidents and disclosures: a critical SQL injection in the LiteLLM Python package (CVE-2026-42208) was exploited within ~36 hours to access/modify databases; a critical GitHub command‑injection leading to remote code execution (CVE-2026-3854) was disclosed; cPanel patched a critical authentication vulnerability affecting all supported versions; CISA added Windows Shell and ConnectWise ScreenConnect issues (including CVE-2024-02-21) to its KEV catalog. Additional notable items: Vimeo data exposure via an Anodot breach exploited by ShinyHunters, a Signal phishing wave

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
84258ba5f372fad5664e5e7f563479218cc902506997f842c5834bbb25397590
Enrichment time
2026-04-30T02:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.