CISA adds actively exploited LiteLLM command-injection flaw CVE-2026-42271 to KEV catalog

CISA says attackers are actively exploiting a critical flaw in BerriAI's LiteLLM, an artificial intelligence gateway used to connect apps to multiple model providers. The bug, CVE-2026-42271, is a command-injection vulnerability, meaning crafted input can make a server run attacker-chosen system commands. CISA added it to the Known Exploited Vulnerabilities catalog, but public details on the attacks remain limited.
Why it matters: Organizations running internet-facing or internally exposed LiteLLM instances should treat this as urgent and patch or isolate affected systems immediately. An actively exploited command-injection flaw can quickly lead to full server compromise and follow-on data theft.

Sources

In Other News: Google Security Layoffs, AudiA6 Takedown, $400 Million Coupang Fine
SecurityWeek News 2026.06.12 100% relevant
This article establishes a distinct tracked event by identifying CVE-2026-42271 in LiteLLM as actively exploited and newly added to CISA's KEV catalog, with concrete action implications for defenders.
← Back to all stories