Skip to content
The Nexus
DossierENTITY

command injection vulnerability

Coverage of command injection vulnerability in the Nexus archive.

Earliest in view: Jun 9 · 06:26 UTCMost recent: Aug 10 · 09:49 UTC
Co-mentioned in this coverage
Recent coverage
  • SECURITYAug 10 · 09:49 UTCBLEEPING COMPUTER
    Critical Progress LoadMaster flaw now actively exploited in attacks

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned about an active threat exploiting a critical-severity flaw. The vulnerability resides in Progress Kemp LoadMaster, which is identified as a command injection weakness.

  • SECURITYJul 27 · 22:49 UTCBLEEPING COMPUTER
    Arista patches VeloCloud Orchestrator zero-day exploited in attacks

    Arista has released a patch for a maximum-severity command injection vulnerability in its on-premises VeloCloud Orchestrator deployments, which is currently being exploited in cyber attacks. The vulnerability, classified as a zero-day, allows attackers to execute arbitrary commands, prompting urgent remediation actions.

  • SECURITYJun 9 · 06:26 UTCTHE HACKER NEWS
    LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE

    CISA added a high-severity command injection vulnerability (CVE-2026-42271) in BerriAI LiteLLM to its KEV catalog due to active exploitation. The flaw allows authenticated users to execute arbitrary commands on affected systems.