GTIG: AI-Era Vulnerability Discovery and Exploitation Surge — In-the-Wild Exploitation of BeyondTrust CVE-2026-1731, LiteLLM CVE-2026-42271 and Langflow CVE-2026-5027

GTIG: AI-Era Vulnerability Discovery and Exploitation Surge (TL-2026-2818), also tracked as AI-Era Vulnerability Exploitation Surge, is a critical-severity software vulnerability scored CVSS 9.9, first published 2026-09-30. It has no confirmed attribution, affects BeyondTrust Remote Support (RS), references 5 CVEs (CVE-2026-1731, CVE-2026-42271, CVE-2026-5027), maps to 14 MITRE ATT&CK techniques (T1005, T1053.003, T1059.004), and is covered by 9 detection rules and 26 indicators of compromise.

Key facts for TL-2026-2818

Threat ID
TL-2026-2818
Also known as
AI-Era Vulnerability Exploitation Surge
Severity
CRITICAL
CVSS
9.9
Status
ACTIVE
Category
VULNERABILITY
First published
2026-09-30
Last reviewed
2026-09-30
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
technology, finance, legal, education, retail, health
Target regions
North America, Europe, australia
Detection rules
9
Indicators of compromise
26

Malware and tooling in GTIG: AI-Era Vulnerability Discovery and Exploitation Surge

Malware and tooling: AgendaCrypt, SNOWLIGHT, SparkRAT, VShell, BeyondTrust, CloudFlare Tunnel, Ligolo-ng

Google Threat Intelligence Group reports disclosures doubled (5,045 in Jan 2026 to 10,477 in Jul 2026) and exploited vulnerabilities rose to 18/month (Jan-Aug 2026) versus 10.5/month in 2025, with 141 distinct exploited vulnerabilities already exceeding 2025's 127. Exploitation is confirmed against AI middleware (LiteLLM CVE-2026-42271, Langflow CVE-2026-5027) and BeyondTrust CVE-2026-1731, which saw multiple threat clusters within days of disclosure deploying SNOWLIGHT, SPARKRAT and cryptominers.

How GTIG: AI-Era Vulnerability Discovery and Exploitation Surge works

Google Threat Intelligence Group (GTIG) published 'Vulnerability Discovery and Exploitation Trends in the AI Era' on 2026-09-30. Monthly CVE disclosures roughly doubled from 5,045 (Jan 2026) to 10,477 (Jul 2026), peaking at 10,740 in Aug 2026. High-risk disclosures rose from 131 to 350 (+167%). Exploitation averaged 18 vulnerabilities/month in Jan-Aug 2026 (10.5/month in 2025); 141 distinct vulnerabilities were exploited in eight months versus 127 in all of 2025, only about 0.23% of disclosures (1 in 431). Zero-days averaged 11/month (8/month in 2025), spiked to 22 in Aug 2026 and made up 62% of exploited vulnerabilities. Edge and security appliances accounted for 14% of exploited flaws (65% of them High/Critical threat risk) because unauthenticated management interfaces sit outside EDR visibility; enterprise directory and collaboration products accounted for 11%. Mass-disclosure events (TOTOLINK router firmware, Apr-May 2026; Oracle and Linux kernel drivers, Jun-Aug 2026) inflated volume.

GTIG reports that AI-discovered vulnerabilities skew toward more consequential classes: 50% lead to remote code execution versus 26% for non-AI-discovered bugs. CVE-2026-1731 (BeyondTrust Remote Support / Privileged Remote Access, unauthenticated OS command injection, discovered autonomously by Hacktron AI) was first exploited about 4 days after disclosure and by 5 additional threat clusters within 7 days, deploying SNOWLIGHT, SPARKRAT and cryptominers, with privilege escalation, lateral movement and data exfiltration. Unit 42 independently documented exploitation via the WebSocket-exposed thin-scc-wrapper script (bash arithmetic-context injection in the remoteVersion parameter), leading to SparkRAT, VShell, web shells (including a China Chopper/AntSword-style aws.php), temporary admin account takeover, SimpleHelp/AnyDesk, Cloudflare Tunnel, Ligolo-ng, Meterpreter, Nezha agent, OAST-based DNS exfiltration and PostgreSQL dumps, across financial, legal, technology, higher-education, retail and healthcare victims in the US, France, Germany, Australia and Canada. BeyondTrust cloud customers were patched 2026-02-02; the advisory and self-hosted patches followed 2026-02-06; CISA added the CVE to KEV on 2026-02-13.

GTIG also tracks AI middleware exploitation. CVE-2026-42271 (BerriAI LiteLLM 1.74.2 through 1.83.6, patched in 1.83.7) is command injection in the MCP preview endpoints POST /mcp-rest/test/connection and /mcp-rest/test/tools/list, where a stdio server configuration (command, args, env) is spawned as a subprocess on the proxy host, yielding host takeover and theft of upstream API credentials; CybelAngel reports it chains with a Starlette host-header validation bypass (CVE-2026-48710) for unauthenticated RCE (CVSS 10.0), was added to CISA KEV on 2026-06-09, and names the Qilin ransomware group as exploiting it (single-source claim, not stated in the GTIG article). CVE-2026-5027 (Langflow <= 1.8.4) is a path traversal in the POST /api/v2/files upload handler where the unsanitized multipart 'filename' allows arbitrary file writes (cron jobs, SSH authorized_keys, webshells); with Langflow's default auto-login it needs no credentials. It was exploited in the wild from June 2026; roughly 7,000 instances are internet-exposed (Censys); fixed in 1.9.0 and later (1.10.0 current as of 2026-06-10). The older Langflow CVE-2025-3248 (unauthenticated Python code injection via /api/v1/validate/code exec()) was added to CISA KEV in May 2025.

GTIG counts 2,076 cumulative AI-stack vulnerabilities (1,500+ in 2026), with agent orchestration frameworks (Flowise, Langflow, LangChain, Dify and others) at 782 in 2026, about half of all AI-related flaws and a +347% increase. GTIG also cites the first known case of a threat actor holding a zero-day exploit script developed with generative AI, intercepted during operational planning (from GTIG's May AI Threat Tracker). No IOCs are in the GTIG article; the IOCs below come from Unit 42's BeyondTrust analysis. The article gives no CVSS scores; scores here come from vendor/third-party sources.

MITRE ATT&CK techniques used in TL-2026-2818

Collection

T1005 Data from Local System

Persistence

T1053.003 Cron; T1098.004 SSH Authorized Keys; T1505.003 Web Shell

Execution

T1059.004 Unix Shell; T1059.006 Python

Command and Control

T1071.004 DNS; T1219 Remote Access Tools; T1572 Protocol Tunneling

Defense Evasion

T1078 Valid Accounts

Initial Access

T1190 Exploit Public-Facing Application

Impact

T1496 Resource Hijacking

Credential Access

T1552 Unsecured Credentials

Resource Development

T1587.004 Exploits

Affected products and versions in GTIG: AI-Era Vulnerability Discovery and Exploitation Surge

  • BeyondTrust — Remote Support (RS)
    Vulnerable versions: 25.3.1 and prior
    Fixed in: 25.3.2 and later (patch BT26-02-RS)
  • BeyondTrust — Privileged Remote Access (PRA)
    Vulnerable versions: 24.3.4 and prior
    Fixed in: 25.1.1 and later (patch BT26-02-PRA)
  • BerriAI — LiteLLM
    Vulnerable versions: 1.74.2 through 1.83.6
    Fixed in: 1.83.7 and later
  • Langflow — Langflow
    Vulnerable versions: 1.8.4 and prior (CVE-2026-5027)
    Fixed in: 1.9.0 and later; 1.10.0

Remediation for GTIG: AI-Era Vulnerability Discovery and Exploitation Surge

Patches

  • BeyondTrust BT26-02-RS / BT26-02-PRA (RS 25.3.2+, PRA 25.1.1+)
  • LiteLLM 1.83.7 and Starlette 1.0.1
  • Langflow 1.9.0 / 1.10.0 (langflow-base 0.8.3)

Immediate actions

  • Patch self-hosted BeyondTrust Remote Support to 25.3.2+ and Privileged Remote Access to 25.1.1+ (BT26-02 advisory) and hunt for web shells, new admin accounts and remote-access tools
  • Upgrade LiteLLM to 1.83.7+ and Starlette to 1.0.1+; block or restrict /mcp-rest/test/* endpoints; rotate all upstream LLM API keys and stored credentials held by the gateway
  • Upgrade Langflow to 1.10.0+ (fix in 1.9.0); disable default auto-login and remove internet exposure of Langflow instances
  • Audit process trees on proxy/orchestration hosts for shells, interpreters and network tools spawned by litellm/langflow processes; check crontabs and ~/.ssh/authorized_keys for unauthorized writes

Workarounds

  • Restrict BeyondTrust management interfaces and WebSocket endpoints to trusted networks
  • Block egress DNS to OAST domains and monitor Cloudflare Tunnel, SimpleHelp and AnyDesk installations on appliance hosts

Longer-term hardening

  • Move from volume patching to threat-intelligence-driven triage prioritizing internet-facing edge appliances and KEV-listed flaws
  • Sandbox and network-isolate autonomous agent and AI orchestration workloads; never expose AI gateways or workflow builders to the internet unauthenticated
  • Compress n-day patch SLAs for edge and AI middleware to days, given exploitation within about 4 days of disclosure
  • Deploy pre-release AI-assisted code review to find flaws before production shipping

CVEs associated with GTIG: AI-Era Vulnerability Discovery and Exploitation Surge

CVE-2026-1731, CVE-2026-42271, CVE-2026-5027, CVE-2025-3248, CVE-2026-48710

Weaknesses (CWE) in GTIG: AI-Era Vulnerability Discovery and Exploitation Surge

CWE-78, CWE-77, CWE-22, CWE-94

Timeline of GTIG: AI-Era Vulnerability Discovery and Exploitation Surge

  • Langflow CVE-2025-3248 (unauthenticated Python code injection via /api/v1/validate/code) added to the CISA Known Exploited Vulnerabilities catalog (May 2025).
  • BeyondTrust automatically patches SaaS/cloud customers for CVE-2026-1731.
  • BeyondTrust releases advisory BT26-02 and fixes for CVE-2026-1731 (unauthenticated OS command injection in Remote Support and Privileged Remote Access, CVSS v4 9.9).
  • CISA adds CVE-2026-1731 to KEV; GTIG reports first exploitation about 4 days after disclosure and 5 additional threat clusters within 7 days.
  • Unit 42 publishes analysis of CVE-2026-1731 exploitation: SparkRAT, VShell, web shells, admin account takeover and OAST DNS exfiltration.
  • Langflow CVE-2026-5027 path traversal in POST /api/v2/files publicly disclosed (found by Tenable); langflow-base 0.8.3 released 2026-03-30.
  • LiteLLM 1.83.7 released fixing CVE-2026-42271 (MCP test endpoint command injection); CVE published the same day.
  • CVE-2026-42271 added to CISA KEV after a chained unauthenticated exploit with Starlette CVE-2026-48710 was confirmed; Qilin reported as exploiting it.
  • Langflow 1.10.0 released; CVE-2026-5027 exploitation observed in the wild (honeypots see file drops), about 7,000 instances exposed.
  • GTIG publishes 'Vulnerability Discovery and Exploitation Trends in the AI Era': 141 exploited vulnerabilities in Jan-Aug 2026 versus 127 in all of 2025; 2,076 cumulative AI-stack CVEs.

Sources cited for GTIG: AI-Era Vulnerability Discovery and Exploitation Surge

More in vulnerability

Detection coverage for TL-2026-2818

As of 2026-09-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2818 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats