LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE

2026-06-09T07:24:06Z5875b9b5e489044745bf9c674342254bcced12e8e5964f89a6b4e2b8b5f441fc
CISAPOCactively_exploitedcloud_abuseespionagekernelmalwarepatchingphishingprivilege_escalationrcesupply_chainvulnerabilitywebshellworm

What happened

Multiple high- and critical-severity incidents and active exploits were reported across open-source and enterprise platforms: CISA added LiteLLM command-injection flaw CVE-2026-42271 to its KEV catalog with evidence of in-the-wild exploitation; a working local root exploit for Linux kernel use-after-free CVE-2026-23111 was published; a critical Check Point IKEv1 certificate-validation bypass CVE-2026-50751 is being actively exploited; SolarWinds Serv-U DoS CVE-2026-28318 was added to KEV; Cisco SD-WAN Manager CVE-2026-20245 is under active exploitation with no patch; Cisco Unified CM CVE-2026-

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
5875b9b5e489044745bf9c674342254bcced12e8e5964f89a6b4e2b8b5f441fc
Enrichment time
2026-06-09T07:24:06Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE · Baitaphish