CISA Adds BerriAI LiteLLM Flaw To KEV Catalog As Exploits Hit Production

CISA added a high-severity LiteLLM command-injection flaw to its Known Exploited Vulnerabilities catalog on June 8, after researchers chained it to a Starlette bypass for unauthenticated RCE.

CISA Adds BerriAI LiteLLM Flaw To KEV Catalog As Exploits Hit Production

The U.S. Cybersecurity and Infrastructure Security Agency on June 8, 2026 added a high-severity command-injection flaw in BerriAI's LiteLLM proxy to its Known Exploited Vulnerabilities catalog, confirming active exploitation against production AI gateways. CISA gave federal agencies until June 22 to remediate.

What CVE-2026-42271 Does

Tracked as CVE-2026-42271 with a CVSS score of 8.7, the bug lets any authenticated LiteLLM user run arbitrary commands on the host. LiteLLM is one of the most widely deployed open-source LLM gateways, routing enterprise traffic across OpenAI, Anthropic, Google, Azure and Bedrock, which means a compromise gives attackers a direct path to credentials, API keys and any model providers stitched behind the proxy.

Network operations center monitoring cybersecurity alerts

The Horizon3 Chain Makes It Worse

Horizon3.ai researchers chained CVE-2026-42271 with CVE-2026-48710, a Starlette host-header validation bypass dubbed BadHost, to skip authentication entirely and pop unauthenticated remote code execution. Once inside, attackers can siphon API keys, pivot into connected AI infrastructure and compromise downstream tools wired into the gateway — a catastrophic blast radius for enterprises that deployed LiteLLM as a control plane.

Check Point Adds A Second Headache

CISA paired the LiteLLM listing with CVE-2026-50751, an authentication-bypass affecting Check Point Quantum Security Gateway. Security teams now juggle two emergency patches at once, with both bugs already reported as exploited. The CISA action lands as AI-native attacks accelerate, including the Claude Mythos-led Glasswing program that has surfaced thousands of bugs and Anthropic's same-day release of Claude Fable 5 with hardened cyber safeguards.

Reporting based on coverage from CISA, The Hacker News and SecurityAffairs.

Category: Cyber Security

Related Articles