CVE-2024-6587: Critical LiteLLM Vulnerability Exploited in AI Infrastructure Attacks
A critical vulnerability in LiteLLM that is being actively exploited by attackers to hijack AI infrastructure and conduct attacks against third parties.
Critical and exploited CVEs, vulnerability intelligence and remediation guidance.
A critical vulnerability in LiteLLM that is being actively exploited by attackers to hijack AI infrastructure and conduct attacks against third parties.
A vulnerability in self-hosted model servers that enables attackers to hijack misconfigured AI infrastructure.
A local privilege escalation vulnerability in polkit's pkexec utility. The attacker staged exploit code for this older flaw alongside the AI agent…
CVE-2026-8496 is a zero-day vulnerability in the SOGo webmail platform exploited by TA458 in March 2026. It was patched in version 5.12.8.
CVE-2026-25243 is a Redis RCE vulnerability patched in May 2026. It is part of the same vulnerability family as the July 2026…
CVE-2026-25589 is associated with memory corruption in RedisBloom during the RESTORE operation. Redis maps this CVE to RedisBloom memory corruption, not the…
On July 23, 2026, Redis shipped seven security releases after researchers published authenticated remote code execution (RCE) proof-of-concept (PoC) exploits for stock…
Eight security flaws in NodeBB were disclosed on July 24, 2026, along with exploit code. Discovered by Aikido Security's AI pentest agents…
A separate NodeBB federation vulnerability, CVE-2026-58593, filed on July 1, 2026, allows an outside server to post and send messages in the…
CVE-2025-66376 is a vulnerability in Zimbra mail servers exploited by Laundry Bear to deliver ZimReaper malware via a view-based exploit requiring only…