Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026051405050404 | Publication Time | 2026-05-14 17:01:05 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026-05-14 17:01:05 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】CISA added 3 known exploited vulnerabilities to the KEV Catalog (2026/05/04-2026/05/10) |
|||
| [Content]
Forwarded from TWCERTCC-200-202605-00000010 【CVE-2026-0300】Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability (CVSS v3.1: 9.8) 【CVE-2026-6973】Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability (CVSS v3.1: 7.2) 【CVE-2026-42208】BerriAI LiteLLM SQL Injection Vulnerability (CVSS v3.1: 9.8) Information Sharing Level: WHITE (The information content is information that may be publicly disclosed) |
|||
| [Affected Platform]
【CVE-2026-0300】Please refer to the affected versions listed by the official source https://security.paloaltonetworks.com/CVE-2026-0300 【CVE-2026-6973】Please refer to the affected versions listed by the official source https://hub.ivanti.com/s/article/May-2026-Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-Multiple-CVEs 【CVE-2026-42208】Please refer to the affected versions listed by the official source https://github.com/BerriAI/litellm/security/advisories/GHSA-r75f-5x8p-qvmc |
|||
| [Recommended Actions]
【CVE-2026-0300】The official source has released a fix update for the vulnerability. Please update to the relevant version 【CVE-2026-6973】The official source has released a fix update for the vulnerability. Please update to the relevant version 【CVE-2026-42208】The official source has released a fix update for the vulnerability. Please update to the relevant version |
|||
|
[Reference] |
|||