DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 13:15:29ZSOURCES: 14CRITICAL: 18
⚠ ACTIVE ALERTS
@GossiTheDog CRITICAL — wp2shell (CVE-2026-63030 + CVE-2026-60137) is being actively exploited in the wild —… /// @MsftSecIntel CRITICAL — Microsoft is tracking active exploitation of CVE-2026-63030 and CVE-2026-60137… /// @vxunderground CRITICAL — wp2shell PoCs are now floating around the internet. Public exploit code for the full… /// @FalconFeedsio CRITICAL — 🔴 Qilin ransomware group has now publicly claimed 2,035+ victims on its dark web leak… /// @TalosSecurity CRITICAL — Talos is tracking mass exploitation of wp2shell (CVE-2026-63030/CVE-2026-60137).…
18Critical Threats
18Active CVEs
10IOCs Tracked
6New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-42271PUBLISHED: 2026-05-08
HIGHCVE-2026-42271★ CISA KEV LISTED

BerriAI LiteLLM MCP Command Injection (Chains to CVSS 10.0 Unauth RCE)

VENDOR: BerriAI//PRODUCT: LiteLLM AI Gateway/Proxy
8.8
HIGH
CVSS 3.1
PATCH STATUS
PATCH AVAILABLE
EXPLOIT STATUS
PUBLIC EXPLOIT

A command injection flaw (CWE-77/78) in LiteLLM's MCP server preview endpoints (POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list) allows any authenticated user — including holders of low-privilege internal-user API keys — to spawn arbitrary OS commands as subprocesses on the proxy host. Horizon3.ai discovered that chaining CVE-2026-42271 with CVE-2026-48710 (a Starlette BadHost header validation bypass) removes the authentication requirement entirely, yielding a combined CVSS 10.0 unauthenticated RCE chain. Successful exploitation exposes all LLM provider API keys (OpenAI, Anthropic, Google, Azure, AWS Bedrock) and AI infrastructure connected through the proxy. CISA added to KEV on June 8, 2026, with a June 22 BOD 22-01 federal deadline. Public PoC and detailed chain analysis are available on GitHub.

Attack Vector
NETWORK
Attack Complexity
LOW
Privs Required
LOW
User Interaction
NONE
Scope / Impact
UNCHANGED
C:H · I:H · A:H
AFFECTED VERSIONSLiteLLM versions 1.74.2 through 1.83.6 (fixed in 1.83.7-stable)
  • https://thehackernews.com/2026/06/litellm-flaw-cve-2026-42271-exploited.html
  • https://github.com/BerriAI/litellm/security/advisories/GHSA-v4p8-mg3p-g94g
  • https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  • https://nvd.nist.gov/vuln/detail/CVE-2026-42271
SHARE BRIEF:✕ Post on Xin Share on LinkedIn