CISA Adds Actively Exploited Linux Root Access Bug CVE-2026-31431 to KEV

2026-05-04T01:24:15Zfbd7b4c500d01f37c1007033ea65c5eee0f0a309fa7b42a5345ad003a4e70647
CISA KEVCVE-2024-1708CVE-2026-31431CVE-2026-3854CVE-2026-42208China-linked espionageGitHub RCEGo modulesGoogle AppSheetPyPIRubyGemsSQL injectionSSO abuseactive exploitationcredential thefthigh-severitylocal privilege escalation (LPE)npmphishingransomware/wiper (VECT 2.0)source code breach (Trellix)supply chain compromisevishing

What happened

The Hacker News roundup highlights multiple high-impact incidents: CISA added a Linux local privilege escalation (CVE-2026-31431, “Copy Fail”) to its KEV list due to active exploitation; critical/rapidly exploited flaws include LiteLLM SQLi (CVE-2026-42208) and a GitHub push-to-RCE (CVE-2026-3854). Widespread supply-chain and credential-theft campaigns were observed (malicious PyPI/npm/Ruby/Go packages, compromised PyTorch Lightning releases, SAP-related npm packages, poisoned gems/modules), plus mass phishing (30k Facebook accounts via Google AppSheet) and fast SaaS extortion using vishing/SS

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
fbd7b4c500d01f37c1007033ea65c5eee0f0a309fa7b42a5345ad003a4e70647
Enrichment time
2026-05-04T01:24:15Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.