LIVE · cybersecurity feed
Live wire
CVE-2026-81578 · PaperCut NG/MF Flaw Exploited Before CVE PublicationCVE-2026-82078 · PaperCut NG/MF Flaw Exploited Before CVE PublicationCVE-2026-83549 · SonicWall SMA1000 OS Command Injection Exploited Same Day as DisclosureCVE-2026-83548 · SonicWall SMA1000 SSRF Flaw Exploited Same Day as DisclosureCVE-2026-82329 · JFrog Artifactory Flaw Exploited Same Day as DisclosureOpenAI Announced $1B in Defensive Tools for Water UtilitiesAttackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS CredentialsCVE-2026-59346 · Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host CodeCVE-2026-32475 · Elementor Pro WordPress Plugin Vulnerability Exploited to Hack SitesBroadcom Patches Critical VMware Workstation and Fusion VM-Escape Vulnerabilities
vendor1 exploited in the wild

Litellm

7 CVEs published in the last four months and 3 stories. Exploited flaws first.

Critical1
High6
Medium0
Exploited (KEV)1

Patch these first

CVECVSSSeverityProductSummaryPublished
CVE-2026-59822exploited8.2highlitellmLiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format.59d ago

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-494689.8criticallitellmLiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format.75d ago
CVE-2026-471028.8highlitellmLiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint.107d ago
CVE-2026-471018.8highlitellmLiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their107d ago
CVE-2026-59822exploited8.2highlitellmLiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format.59d ago
CVE-2026-127957.3highlitellmA vulnerability was determined in BerriAI litellm up to 1.82.2.77d ago
CVE-2026-127737.3highlitellmA weakness has been identified in BerriAI litellm up to 1.59.8.77d ago
CVE-2026-598217.2highlitellmLiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format.59d ago

Filter the full tracker by Litellm

Our coverage of Litellm

breach

LiteLLM Supply-Chain Attack – Technology, Banking and Healthcare the Most Affected

The SANDCLOCK LiteLLM supply-chain attack exposed credentials across 2,038 repositories, affecting technology, finance, healthcare, retail and more. Resecurity (USA) estimated the most affected sectors by the “SANDCLOCK” backdoor, which was planted as a result of the code repository compromise. According to cybersecurity experts, LiteLLM / TeamPCP Supply-Chain Attack will have long-lasting consequ

breach

Trivy, Not LiteLLM Behind the 2,500 Org Compromise

Over 95% of the affected companies were exposed before the malicious LiteLLM packages were published. The post Trivy, Not LiteLLM Behind the 2,500 Org Compromise appeared first on SecurityWeek.

ai

153GB of stolen credentials surface after LiteLLM supply chain attack

A massive 153GB archive stolen during the LiteLLM supply chain attack exposes credentials and other sensitive data linked to thousands of corporate domains, including AWS, Samsung, Cisco, and Salesforce. Hudson Rock says it obtained and analyzed the archive, which contains 433,909 files, and attributed 118,829 CI runner dumps to 2,488 corporate domains. “We are leveraging this data for a global et