VulnWatch VulnWatch
← Back to dashboard
Unknown rss_thehackernews · rss_ba5c55b4a325572df422f7a3807619e9

LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE

Published Jun 9, 2026

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity flaw impacting BerriAI LiteLLM to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

The vulnerability, tracked as CVE-2026-42271 (CVSS score: 8.7), is a command injection vulnerability that could allow any authenticated user to run arbitrary commands on the

Affected AI Products

litellm
Get the weekly digest. Every Monday: top AI security stories of the week. Free.