High 8.7
KEV-listed
CVE-2026-42271
LiteLLM MCP Server Exploited via CVE-2026-42271 with Cryptominer Deployment
Vendor / product: LiteLLM MCP server
Event date: 2026-06-09
Public PoC: Yes
First tracked by RiskWire: 2026-08-28
CISA KEV catalog
Added to KEV
Federal remediation due
2026-06-22 (90 days overdue)
Ransomware campaign use
Unknown
CISA description
BerriAI LiteLLM contains a command injection vulnerability that could allow any authenticated user, including holders of low-privilege internal-user keys, to run arbitrary commands on the host.
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Named threat actors
Qilin
Sources & citations (2)
- Attackers Exploit MCP RCE, Blind Prompt Injection and Memory Credential Theft Against AI Infrastructure gbhackers.com · 2026-08-28
- Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft cybersecuritynews.com · 2026-08-28
References
See CVE-2026-42271 in context
RiskWire tracks every exploited CVE this week, cross-referenced against CISA KEV with federal remediation deadlines. Filtered to your vendor stack.
Book a 20-min demo →