Executive Summary
On June 8, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: CVE-2026-42271 and CVE-2026-50751. CVE-2026-42271 affects BerriAI's LiteLLM versions 1.74.2 through 1.83.6, where certain endpoints allow authenticated users to execute arbitrary commands on the host system. CVE-2026-50751 impacts Check Point's Remote Access VPN and Mobile Access products using the deprecated IKEv1 protocol, enabling unauthenticated attackers to establish VPN sessions without valid credentials. Both vulnerabilities have been actively exploited, posing significant risks to federal enterprises. (nvd.nist.gov)
The inclusion of these vulnerabilities in the KEV Catalog underscores the critical need for organizations to promptly address known security flaws. As cyber threats evolve, timely remediation of such vulnerabilities is essential to maintain robust security postures and protect sensitive information from unauthorized access.
Why This Matters Now
The active exploitation of CVE-2026-42271 and CVE-2026-50751 highlights the urgency for organizations to patch these vulnerabilities immediately. Delayed remediation increases the risk of unauthorized access and potential data breaches, emphasizing the importance of proactive vulnerability management.
Attack Path Analysis
Attackers exploited CVE-2026-42271 in BerriAI LiteLLM to gain initial access, then escalated privileges by exploiting CVE-2026-50751 in Check Point Security Gateway. They moved laterally within the network, established command and control channels, exfiltrated sensitive data, and caused significant operational disruption.
Kill Chain Progression
Initial Compromise
Description
Attackers exploited CVE-2026-42271 in BerriAI LiteLLM to gain unauthorized access.
Related CVEs
CVE-2026-42271
CVSS 8.8Authenticated users with low-privilege API keys can execute arbitrary commands on the proxy host due to insufficient role checks on two preview endpoints in LiteLLM versions 1.74.2 to before 1.83.7.
Affected Products:
BerriAI LiteLLM – >= 1.74.2, < 1.83.7
Exploit Status:
exploited in the wildCVE-2026-50751
CVSS 9.3A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.
Affected Products:
Check Point Remote Access VPN – All versions using deprecated IKEv1 without machine certificate requirement
Check Point Mobile Access – All versions using deprecated IKEv1 without machine certificate requirement
Check Point Spark Firewall – All versions using deprecated IKEv1 without machine certificate requirement
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Valid Accounts
Command and Scripting Interpreter
Create Account
Application Layer Protocol
Remote Services
Network Service Scanning
Data Destruction
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Access Controls and Identity Management
Control ID: 500.07
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity Verification and Authentication
Control ID: Pillar 1: Identity
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Federal agencies face mandatory remediation under BOD 22-01 for Check Point gateway authentication vulnerabilities, requiring immediate security controls and compliance validation.
Computer Software/Engineering
BerriAI LiteLLM command injection vulnerability directly impacts AI/ML development platforms, requiring enhanced egress security and zero trust segmentation for cloud-native applications.
Financial Services
Known exploited vulnerabilities threaten encrypted traffic flows and east-west communications, demanding strengthened firewall controls and PCI compliance validation measures.
Health Care / Life Sciences
Authentication bypass and command injection vectors compromise HIPAA-regulated data flows, necessitating enhanced threat detection and multicloud visibility capabilities.
Sources
- CISA Adds Two Known Exploited Vulnerabilities to Cataloghttps://www.cisa.gov/news-events/alerts/2026/06/08/cisa-adds-two-known-exploited-vulnerabilities-catalogVerified
- Check Point Releases Important Hotfix for Vulnerabilities in Deprecated IKEv1 VPN Protocolhttps://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/Verified
- LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCEhttps://thehackernews.com/2026/06/litellm-flaw-cve-2026-42271-exploited.htmlVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Implementing Aviatrix Zero Trust CNSF could have significantly limited the attacker's ability to escalate privileges, move laterally, and exfiltrate data, thereby reducing the overall impact of the incident.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's initial access may have been constrained, potentially limiting their ability to exploit the vulnerability and gain unauthorized entry.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges could have been limited, reducing their access to critical systems.
Control: East-West Traffic Security
Mitigation: Lateral movement within the network may have been restricted, limiting the attacker's reach to other systems.
Control: Multicloud Visibility & Control
Mitigation: The establishment of command and control channels could have been detected and disrupted, reducing the attacker's ability to maintain access.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration attempts may have been identified and blocked, limiting the attacker's ability to remove sensitive information.
The overall impact of the attack could have been reduced, limiting operational disruption and data loss.
Impact at a Glance
Affected Business Functions
- Remote Access Services
- VPN Connectivity
- AI Gateway Operations
Estimated downtime: 7 days
Estimated loss: $500,000
Potential exposure of sensitive corporate data due to unauthorized access via exploited vulnerabilities.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Inline IPS (Suricata) to detect and prevent exploitation of known vulnerabilities.
- • Deploy Zero Trust Segmentation to limit lateral movement within the network.
- • Utilize East-West Traffic Security to monitor and control internal traffic flows.
- • Enforce Egress Security & Policy Enforcement to prevent unauthorized data exfiltration.
- • Enhance Threat Detection & Anomaly Response capabilities to identify and respond to suspicious activities promptly.



