CISA Active Exploit Catalog Expands with Critical Gateway Flaws
ID: 00758ad1-774b-5a7d-9a0c-9307e10abf41
STIX ID: report--00758ad1-774b-5a7d-9a0c-9307e10abf41
Feed Name: securityonline.info
CISA updated its active exploit catalog to include two high-severity flaws: a command-injection parsing bug in BerriAI LiteLLM (CVE-2026-42271, CVSS 8.7) that permits authenticated low-privilege operators to run arbitrary OS commands, and an authentication-bypass in Check Point Remote Access VPN/Mobile Access (CVE-2026-50751, CVSS 9.3) that enables unauthenticated remote access; both are being actively weaponized in the wild and at least one intrusion has been linked to the Qilin ransomware operation, so administrators are urged to apply vendor fixes or implement immediate access mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
