CISA Adds Actively Exploited Linux Root Access Bug CVE-2026-31431 to KEV

2026-05-03T07:24:09Zcf300b0a10a6df563d801f4e8b1958a5cf9a7e6d377d7ff005bcebd40f3090df
AppSheetCISA‑KEVConnectWiseGitHub‑RCEGoLinuxPyPIRubyGemsSSO‑abuseaccount‑takeoverbackdoorcPanelcredential‑theftdestructive‑malwareespionageknown‑exploited‑vulnerabilitylocal‑privilege‑escalationnpmphishingransomwarerapid‑extortionsource‑code‑breachsupply‑chain‑attackvishing

What happened

A batch of high‑impact security incidents and active exploitation was reported: CISA added the Linux local‑privilege‑escalation bug CVE-2026-31431 (Copy Fail) to its KEV list; researchers disclosed multiple fast‑exploited supply‑chain compromises (PyTorch Lightning malicious releases, poisoned Ruby gems and Go modules, SAP‑related npm packages, and an npm package abused with AI-inserted malware); a critical GitHub command‑injection RCE (CVE-2026-3854) and a quickly exploited LiteLLM SQLi (CVE-2026-42208) were published; Trellix confirmed unauthorized source‑code repository access; a Vietnamese

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
cf300b0a10a6df563d801f4e8b1958a5cf9a7e6d377d7ff005bcebd40f3090df
Enrichment time
2026-05-03T07:24:09Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.