CISA Adds Actively Exploited Linux Root Access Bug CVE-2026-31431 to KEV

2026-05-03T19:24:12Ze3614059a110bb9d8c2df9d96dcfebb111ae95bf59bab7cdf71ade589c425167
CISA-KEVactive-exploitationcredential-theftespionagelinuxlocal-privilege-escalationphishingransomwaresoftware-supply-chainsource-code-breachsso-abusesupply-chain-attack

What happened

A large batch of active and high-impact incidents: CISA added a Linux local privilege escalation (Copy Fail) tracked as CVE-2026-31431 (CVSS 7.8) to its KEV catalog after evidence of in-the-wild exploitation. Multiple supply-chain and credential-theft campaigns were reported — including poisoned Ruby/Go modules, compromised PyPI/PyTorch Lightning releases, and Mini Shai‑Hulud npm activity — plus rapid exploitation of LiteLLM SQLi CVE-2026-42208. Critical platform flaws were disclosed including GitHub RCE CVE-2026-3854 and a ConnectWise path traversal (CVE-2024-1708) added to KEV; enterprise- &

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
e3614059a110bb9d8c2df9d96dcfebb111ae95bf59bab7cdf71ade589c425167
Enrichment time
2026-05-03T19:24:12Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · CISA Adds Actively Exploited Linux Root Access Bug CVE-2026-31431 to KEV · Baitaphish