logo

CISA Active Exploit Catalog Expands with Critical Gateway Flaws

ID: 00758ad1-774b-5a7d-9a0c-9307e10abf41

STIX ID: report--00758ad1-774b-5a7d-9a0c-9307e10abf41

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-06-09

Date Updated: 2026-06-09

Author: Do Son

...
...

CISA updated its active exploit catalog to include two high-severity flaws: a command-injection parsing bug in BerriAI LiteLLM (CVE-2026-42271, CVSS 8.7) that permits authenticated low-privilege operators to run arbitrary OS commands, and an authentication-bypass in Check Point Remote Access VPN/Mobile Access (CVE-2026-50751, CVSS 9.3) that enables unauthenticated remote access; both are being actively weaponized in the wild and at least one intrusion has been linked to the Qilin ransomware operation, so administrators are urged to apply vendor fixes or implement immediate access mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.