CISA Adds Actively Exploited Linux Root Access Bug CVE-2026-31431 to KEV
2026-05-04T01:24:15Z•fbd7b4c500d01f37c1007033ea65c5eee0f0a309fa7b42a5345ad003a4e70647
CISA KEVCVE-2024-1708CVE-2026-31431CVE-2026-3854CVE-2026-42208China-linked espionageGitHub RCEGo modulesGoogle AppSheetPyPIRubyGemsSQL injectionSSO abuseactive exploitationcredential thefthigh-severitylocal privilege escalation (LPE)npmphishingransomware/wiper (VECT 2.0)source code breach (Trellix)supply chain compromisevishing
What happened
The Hacker News roundup highlights multiple high-impact incidents: CISA added a Linux local privilege escalation (CVE-2026-31431, “Copy Fail”) to its KEV list due to active exploitation; critical/rapidly exploited flaws include LiteLLM SQLi (CVE-2026-42208) and a GitHub push-to-RCE (CVE-2026-3854). Widespread supply-chain and credential-theft campaigns were observed (malicious PyPI/npm/Ruby/Go packages, compromised PyTorch Lightning releases, SAP-related npm packages, poisoned gems/modules), plus mass phishing (30k Facebook accounts via Google AppSheet) and fast SaaS extortion using vishing/SS
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- fbd7b4c500d01f37c1007033ea65c5eee0f0a309fa7b42a5345ad003a4e70647
- Enrichment time
- 2026-05-04T01:24:15Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.