LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers

2026-06-15T19:24:09Z5accdd16ed4be554b5ec7bc57d8da78d4bfa613e2554cb152d4e3593ae71eae2
AI-agent attacksActive exploitationAgentjackingArch AUR compromiseBitLocker GreatXMLChrome extension adwareCrypto laundering (AudiA6)LangGraphLiteLLMMicrosoft 365 Copilot (SearchLeak)OpenClawOracle PeopleSoftPAN-OS GlobalProtectPhishing/PhaaS (Sniper Dz)Ransomware (The Gentlemen)Splunk EnterpriseVulnerability managementWordPress supply-chain backdoorZero-day/0-dayeBPF rootkit

What happened

A high-risk week in enterprise and AI security: researchers disclosed multiple vulnerability chains and active exploits that enable server takeover, RCE, data exfiltration, and persistence. Notable incidents include a LiteLLM proxy privilege-escalation chain, Splunk Enterprise unauthenticated RCE (CVE-2026-20253, CVSS 9.8), active exploitation of a PAN-OS GlobalProtect authentication bypass (CVE-2026-0257), Oracle PeopleSoft zero-day exploitation (CVE-2026-35273), several AI-agent attacks (Agentjacking, LangGraph, OpenClaw), a BitLocker bypass (GreatXML), large-scale supply-chain and extension

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
5accdd16ed4be554b5ec7bc57d8da78d4bfa613e2554cb152d4e3593ae71eae2
Enrichment time
2026-06-15T19:24:09Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.