Fresh LiteLLM Vulnerability Exploited Shortly After Disclosure

2026-04-29T13:24:17Z4c0794b7fcf4d02c055ed9a1a418e026c1c162083bef7106b5681036d08ffce4
AI agentsCVE-2026-3854CheckmarxChrome 147Firefox 150GitHubHandalaICS/OTLiteLLMOpenEMRRDPShinyHuntersVNCVimeoWhatsAppagentic securitycyber insurancedata exfiltrationmedical softwarenation-statesupply chain

What happened

This feed highlights multiple active and high-impact security issues: an exploited LiteLLM proxy flaw that allows reading and potential modification of proxy databases; a critical GitHub RCE (CVE-2026-3854) affecting GitHub.com and Enterprise Server; browser fixes (Chrome 147, Firefox 150) addressing critical/high arbitrary code execution bugs; 38 vulnerabilities in OpenEMR that could expose/alter patient data; tens of thousands of Internet-facing RDP/VNC servers exposing ICS/OT assets; a Checkmarx supply-chain data exfiltration from GitHub; a ShinyHunters ransom/extortion data breach at Vimeo

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
4c0794b7fcf4d02c055ed9a1a418e026c1c162083bef7106b5681036d08ffce4
Enrichment time
2026-04-29T13:24:17Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.