Security/ security · cisa · cisco · android

CISA Adds Six Actively Exploited Flaws to Vulnerability Catalog

Three June advisories flag active exploitation across Cisco SD-WAN, Android, Linux, LiteLLM, and Check Point, while a new federal directive tightens patching rules.

CISA Adds Six Actively Exploited Flaws to Vulnerability Catalog

CISA added six vulnerabilities to its Known Exploited Vulnerabilities catalog across three separate advisories in early June, covering products from Cisco and Check Point to Android and an AI proxy tool.

The additions arrived in three batches. On June 2, CISA flagged an integer overflow in the Android Framework (CVE-2025-48595) and a four-year-old improper authentication flaw in the Linux Kernel (CVE-2022-0492) that is still being actively exploited. The June 8 advisory added a command injection bug in BerriAI's LiteLLM (CVE-2026-42271) and an improper authentication vulnerability in Check Point's Security Gateway (CVE-2026-50751). The June 15 batch covers a path traversal flaw in Cisco Catalyst SD-WAN Manager (CVE-2026-20262) and a symlink-following vulnerability in LiteSpeed's cPanel Plugin (CVE-2026-54420). That last advisory also introduced BOD 26-04, a new federal directive updating the older BOD 22-01: agencies must now prioritize patching on publicly exposed assets where exploitation hands an attacker full system control, and must verify whether a system was already compromised before a patch was applied.

The LiteLLM entry stands out. It is an open-source proxy that routes API calls to various AI providers, and a command injection flaw in it being actively exploited suggests attackers are now treating AI infrastructure as a target class, not an edge case. BOD 26-04's "was the system already compromised?" requirement is also more operationally demanding than anything its predecessor asked for.

CVE-2022-0492, a Linux Kernel flaw from 2022, is a useful reminder that "old vulnerability" and "patched vulnerability" are not the same thing.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →