LiteLLM is a tool tracked across 29 threat clusters and 50 intelligence report mentions on ThreatCluster. First observed March 24, 2026; most recent activity July 23, 2026.
A critical command injection vulnerability, CVE-2026-42271, in LiteLLM, an open-source AI gateway, allows unauthenticated remote code execution (RCE) when chained with CVE-2026-48710, a Host header validation bypass in…
CISA has mandated federal agencies to patch a critical vulnerability in Check Point VPN products within 72 hours due to active exploitation by the Qilin ransomware group. The vulnerability, tracked as CVE-2026-42271,…
On March 24, 2026, two versions of the LiteLLM Python package (1.82.7 and 1.82.8) were compromised on PyPI, embedding credential-stealing payloads. The attack, linked to the TeamPCP threat actor, exploited a…
Hackers are exploiting a critical SQL injection vulnerability in the LiteLLM open-source large-language model gateway, tracked as CVE-2026-42208. This pre-authentication flaw allows attackers to access sensitive…
Two critical vulnerabilities (CVE-2026-47101 and CVE-2026-47102) have been identified in LiteLLM versions prior to 1.83.14. CVE-2026-47101 allows authenticated internal users to create API keys with unauthorized access,…
On March 24, 2026, two malicious versions of the LiteLLM Python package (1.82.7 and 1.82.8) were published on PyPI, containing credential-stealing malware. The attack, attributed to the TeamPCP threat group, exploited…
A severe vulnerability known as BadHost (CVE-2026-48710) has been identified in the Starlette framework, affecting millions of AI applications, including those built on FastAPI. This flaw allows unauthenticated…
AI recruiting startup Mercor confirmed it was impacted by a supply chain attack linked to the LiteLLM project, which has affected thousands of organizations. The breach was attributed to the hacking group TeamPCP, with…
Checkmarx, a software security firm, is investigating a significant data leak after its GitHub repository was compromised in a supply-chain attack on March 23, 2026. The attack, attributed to the TeamPCP cybercrime…
xpl0itrs, a financially motivated threat actor group, has announced the launch of a data leak site on June 17, 2026, claiming access to over a dozen major companies. The group, known for its collaboration with TeamPCP,…