All KEV additions

CISA KEV digest

CISA KEV 08 Jun 2026: 2 exploited flaws in BerriAI and Check Point

2 vulnerabilities1 with known ransomware use
Conceptual illustration: A balanced still life of router, workstation, browser panel and software package cube unified by a protective patch shield. Headline: MULTI-VENDOR SECURITY UPDATE.

AI-generated illustration by CyberShitty. Not a photograph or a document from the organisations named.

On 8 June 2026, CISA added 2 actively exploited vulnerabilities affecting BerriAI, Check Point to its Known Exploited Vulnerabilities catalog. If you run any of these products, patch or mitigate now — exploitation is already happening.

CVE-2026-42271Federal deadline

In this section

BerriAI LiteLLM Command Injection Vulnerability

BerriAI / LiteLLM / CWE-78, CWE-77

BerriAI LiteLLM contains a command injection vulnerability that could allow any authenticated user, including holders of low-privilege internal-user keys, to run arbitrary commands on the host.

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-50751Known ransomware useFederal deadline

Check Point Security Gateway Improper Authentication Vulnerability

Check Point / Security Gateway / CWE-287

Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.