VYPR
AI Brief2026-06-10· generated Jun 10, 2026

KEV Additions, SAP Patches, Chrome Vulnerabilities

Palo Alto Networks and LiteLLM flaws added to KEV as actively exploited; SAP patches critical NetWeaver issues; Chrome fixes numerous high-severity vulnerabilities.

CISA has added CVE-2026-0257, an authentication bypass vulnerability in Palo Alto Networks' PAN-OS GlobalProtect portal and gateway, to its Known Exploited Vulnerabilities (KEV) catalog. This flaw allows unauthenticated attackers to bypass security restrictions and establish unauthorized VPN connections. The vulnerability has been observed under active exploitation, underscoring the urgency for organizations to patch their systems. As CyberScoop reported, exploitation has been ongoing for weeks, with multiple security researchers and vendors, including Rapid7, confirming its active use in the wild.

The LiteLLM AI Gateway is facing active exploitation due to CVE-2026-42271, a critical vulnerability that allows unauthenticated attackers to execute arbitrary commands. This flaw, affecting versions prior to 1.83.7, resides in two endpoints used for testing and saving MCP server configurations. Help Net Security and The Hacker News both highlighted that CISA has added this vulnerability to the KEV catalog, emphasizing its immediate threat. Successful exploitation could lead to full system compromise.

SAP has released critical security patches for multiple vulnerabilities, including CVE-2026-27671 and CVE-2026-44748. CVE-2026-27671, found in SAP NetWeaver Application Server ABAP and ABAP Platform, allows unauthenticated attackers to exploit logical errors in memory management via crafted RFC requests, potentially leading to system compromise. CVE-2026-44748 permits authenticated attackers to tamper with signed XML documents, resulting in the acceptance of modified data. BleepingComputer and SecurityWeek covered these patches, noting the high severity of the disclosed issues.

Google Chrome has seen a significant number of vulnerabilities addressed in its latest update, including CVE-2026-11697, CVE-2026-11671, CVE-2026-11659, and CVE-2026-11654. These flaws, rated as High severity by Chromium, range from insufficient input validation to use-after-free errors and integer overflows, with the potential for sandbox escapes. While not yet on the KEV list, the sheer volume and nature of these vulnerabilities in a widely used browser warrant immediate attention and patching, as detailed by Vypr Intelligence.

Fortinet products are affected by two critical vulnerabilities, CVE-2025-59718 and CVE-2025-59719, related to improper verification of cryptographic signatures. CVE-2025-59718 impacts FortiOS versions 7.0 through 7.6, while CVE-2025-59719 affects FortiWeb versions 7.4 through 8.0. These flaws could allow attackers to bypass authentication mechanisms, potentially leading to unauthorized access or control over the affected devices. Prompt patching is advised to mitigate these risks.

Several other critical vulnerabilities have been disclosed across various platforms. These include CVE-2026-49777 and CVE-2017-20251 affecting WordPress plugins, CVE-2026-7486 in Netcad Software's E-İmar allowing SQL injection, and CVE-2026-39910 in STACKIT IaaS API enabling privilege escalation. Additionally, CVE-2026-25555 in OpenBullet2 allows authentication bypass, and CVE-2026-45748 and CVE-2026-45744 in Termix SSH facilitate unauthorized access and command injection, respectively. These diverse vulnerabilities highlight the broad attack surface organizations must manage.

Synthesized by Vypr AI