CISA KEV 08 Jun 2026: 2 exploited flaws in BerriAI and Check Point
2 vulnerabilities1 with known ransomware use
AI-generated illustration by CyberShitty. Not a photograph or a document from the organisations named.
On 8 June 2026, CISA added 2 actively exploited vulnerabilities affecting BerriAI, Check Point to its Known Exploited Vulnerabilities catalog. If you run any of these products, patch or mitigate now — exploitation is already happening.
CVE-2026-42271Federal deadline
In this section
BerriAI LiteLLM Command Injection Vulnerability
BerriAI / LiteLLM / CWE-78, CWE-77
BerriAI LiteLLM contains a command injection vulnerability that could allow any authenticated user, including holders of low-privilege internal-user keys, to run arbitrary commands on the host.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Check Point Security Gateway Improper Authentication Vulnerability
Check Point / Security Gateway / CWE-287
Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.