CISA Adds Actively Exploited Linux Root Access Bug CVE-2026-31431 to KEV
2026-05-03T07:24:09Z•cf300b0a10a6df563d801f4e8b1958a5cf9a7e6d377d7ff005bcebd40f3090df
AppSheetCISA‑KEVConnectWiseGitHub‑RCEGoLinuxPyPIRubyGemsSSO‑abuseaccount‑takeoverbackdoorcPanelcredential‑theftdestructive‑malwareespionageknown‑exploited‑vulnerabilitylocal‑privilege‑escalationnpmphishingransomwarerapid‑extortionsource‑code‑breachsupply‑chain‑attackvishing
What happened
A batch of high‑impact security incidents and active exploitation was reported: CISA added the Linux local‑privilege‑escalation bug CVE-2026-31431 (Copy Fail) to its KEV list; researchers disclosed multiple fast‑exploited supply‑chain compromises (PyTorch Lightning malicious releases, poisoned Ruby gems and Go modules, SAP‑related npm packages, and an npm package abused with AI-inserted malware); a critical GitHub command‑injection RCE (CVE-2026-3854) and a quickly exploited LiteLLM SQLi (CVE-2026-42208) were published; Trellix confirmed unauthorized source‑code repository access; a Vietnamese
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- cf300b0a10a6df563d801f4e8b1958a5cf9a7e6d377d7ff005bcebd40f3090df
- Enrichment time
- 2026-05-03T07:24:09Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.