CISA Adds Actively Exploited Linux Root Access Bug CVE-2026-31431 to KEV
2026-05-03T19:24:12Z•e3614059a110bb9d8c2df9d96dcfebb111ae95bf59bab7cdf71ade589c425167
CISA-KEVactive-exploitationcredential-theftespionagelinuxlocal-privilege-escalationphishingransomwaresoftware-supply-chainsource-code-breachsso-abusesupply-chain-attack
What happened
A large batch of active and high-impact incidents: CISA added a Linux local privilege escalation (Copy Fail) tracked as CVE-2026-31431 (CVSS 7.8) to its KEV catalog after evidence of in-the-wild exploitation. Multiple supply-chain and credential-theft campaigns were reported — including poisoned Ruby/Go modules, compromised PyPI/PyTorch Lightning releases, and Mini Shai‑Hulud npm activity — plus rapid exploitation of LiteLLM SQLi CVE-2026-42208. Critical platform flaws were disclosed including GitHub RCE CVE-2026-3854 and a ConnectWise path traversal (CVE-2024-1708) added to KEV; enterprise- &
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- e3614059a110bb9d8c2df9d96dcfebb111ae95bf59bab7cdf71ade589c425167
- Enrichment time
- 2026-05-03T19:24:12Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.