GTIG: AI-Era Vulnerability Discovery and Exploitation Surge — In-the-Wild Exploitation of BeyondTrust CVE-2026-1731, LiteLLM CVE-2026-42271 and Langflow CVE-2026-5027
GTIG: AI-Era Vulnerability Discovery and Exploitation Surge (TL-2026-2818), also tracked as AI-Era Vulnerability Exploitation Surge, is a critical-severity software vulnerability scored CVSS 9.9, first published 2026-09-30. It has no confirmed attribution, affects BeyondTrust Remote Support (RS), references 5 CVEs (CVE-2026-1731, CVE-2026-42271, CVE-2026-5027), maps to 14 MITRE ATT&CK techniques (T1005, T1053.003, T1059.004), and is covered by 9 detection rules and 26 indicators of compromise.
Key facts for TL-2026-2818
- Threat ID
- TL-2026-2818
- Also known as
- AI-Era Vulnerability Exploitation Surge
- Severity
- CRITICAL
- CVSS
- 9.9
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-09-30
- Last reviewed
- 2026-09-30
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- technology, finance, legal, education, retail, health
- Target regions
- North America, Europe, australia
- Detection rules
- 9
- Indicators of compromise
- 26
Malware and tooling in GTIG: AI-Era Vulnerability Discovery and Exploitation Surge
Malware and tooling: AgendaCrypt, SNOWLIGHT, SparkRAT, VShell, BeyondTrust, CloudFlare Tunnel, Ligolo-ng
Google Threat Intelligence Group reports disclosures doubled (5,045 in Jan 2026 to 10,477 in Jul 2026) and exploited vulnerabilities rose to 18/month (Jan-Aug 2026) versus 10.5/month in 2025, with 141 distinct exploited vulnerabilities already exceeding 2025's 127. Exploitation is confirmed against AI middleware (LiteLLM CVE-2026-42271, Langflow CVE-2026-5027) and BeyondTrust CVE-2026-1731, which saw multiple threat clusters within days of disclosure deploying SNOWLIGHT, SPARKRAT and cryptominers.
How GTIG: AI-Era Vulnerability Discovery and Exploitation Surge works
Google Threat Intelligence Group (GTIG) published 'Vulnerability Discovery and Exploitation Trends in the AI Era' on 2026-09-30. Monthly CVE disclosures roughly doubled from 5,045 (Jan 2026) to 10,477 (Jul 2026), peaking at 10,740 in Aug 2026. High-risk disclosures rose from 131 to 350 (+167%). Exploitation averaged 18 vulnerabilities/month in Jan-Aug 2026 (10.5/month in 2025); 141 distinct vulnerabilities were exploited in eight months versus 127 in all of 2025, only about 0.23% of disclosures (1 in 431). Zero-days averaged 11/month (8/month in 2025), spiked to 22 in Aug 2026 and made up 62% of exploited vulnerabilities. Edge and security appliances accounted for 14% of exploited flaws (65% of them High/Critical threat risk) because unauthenticated management interfaces sit outside EDR visibility; enterprise directory and collaboration products accounted for 11%. Mass-disclosure events (TOTOLINK router firmware, Apr-May 2026; Oracle and Linux kernel drivers, Jun-Aug 2026) inflated volume.
GTIG reports that AI-discovered vulnerabilities skew toward more consequential classes: 50% lead to remote code execution versus 26% for non-AI-discovered bugs. CVE-2026-1731 (BeyondTrust Remote Support / Privileged Remote Access, unauthenticated OS command injection, discovered autonomously by Hacktron AI) was first exploited about 4 days after disclosure and by 5 additional threat clusters within 7 days, deploying SNOWLIGHT, SPARKRAT and cryptominers, with privilege escalation, lateral movement and data exfiltration. Unit 42 independently documented exploitation via the WebSocket-exposed thin-scc-wrapper script (bash arithmetic-context injection in the remoteVersion parameter), leading to SparkRAT, VShell, web shells (including a China Chopper/AntSword-style aws.php), temporary admin account takeover, SimpleHelp/AnyDesk, Cloudflare Tunnel, Ligolo-ng, Meterpreter, Nezha agent, OAST-based DNS exfiltration and PostgreSQL dumps, across financial, legal, technology, higher-education, retail and healthcare victims in the US, France, Germany, Australia and Canada. BeyondTrust cloud customers were patched 2026-02-02; the advisory and self-hosted patches followed 2026-02-06; CISA added the CVE to KEV on 2026-02-13.
GTIG also tracks AI middleware exploitation. CVE-2026-42271 (BerriAI LiteLLM 1.74.2 through 1.83.6, patched in 1.83.7) is command injection in the MCP preview endpoints POST /mcp-rest/test/connection and /mcp-rest/test/tools/list, where a stdio server configuration (command, args, env) is spawned as a subprocess on the proxy host, yielding host takeover and theft of upstream API credentials; CybelAngel reports it chains with a Starlette host-header validation bypass (CVE-2026-48710) for unauthenticated RCE (CVSS 10.0), was added to CISA KEV on 2026-06-09, and names the Qilin ransomware group as exploiting it (single-source claim, not stated in the GTIG article). CVE-2026-5027 (Langflow <= 1.8.4) is a path traversal in the POST /api/v2/files upload handler where the unsanitized multipart 'filename' allows arbitrary file writes (cron jobs, SSH authorized_keys, webshells); with Langflow's default auto-login it needs no credentials. It was exploited in the wild from June 2026; roughly 7,000 instances are internet-exposed (Censys); fixed in 1.9.0 and later (1.10.0 current as of 2026-06-10). The older Langflow CVE-2025-3248 (unauthenticated Python code injection via /api/v1/validate/code exec()) was added to CISA KEV in May 2025.
GTIG counts 2,076 cumulative AI-stack vulnerabilities (1,500+ in 2026), with agent orchestration frameworks (Flowise, Langflow, LangChain, Dify and others) at 782 in 2026, about half of all AI-related flaws and a +347% increase. GTIG also cites the first known case of a threat actor holding a zero-day exploit script developed with generative AI, intercepted during operational planning (from GTIG's May AI Threat Tracker). No IOCs are in the GTIG article; the IOCs below come from Unit 42's BeyondTrust analysis. The article gives no CVSS scores; scores here come from vendor/third-party sources.
MITRE ATT&CK techniques used in TL-2026-2818
Collection
Persistence
T1053.003 Cron; T1098.004 SSH Authorized Keys; T1505.003 Web Shell
Execution
T1059.004 Unix Shell; T1059.006 Python
Command and Control
T1071.004 DNS; T1219 Remote Access Tools; T1572 Protocol Tunneling
Defense Evasion
Initial Access
T1190 Exploit Public-Facing Application
Impact
Credential Access
Resource Development
Affected products and versions in GTIG: AI-Era Vulnerability Discovery and Exploitation Surge
- BeyondTrust — Remote Support (RS)
Vulnerable versions: 25.3.1 and prior
Fixed in: 25.3.2 and later (patch BT26-02-RS) - BeyondTrust — Privileged Remote Access (PRA)
Vulnerable versions: 24.3.4 and prior
Fixed in: 25.1.1 and later (patch BT26-02-PRA) - BerriAI — LiteLLM
Vulnerable versions: 1.74.2 through 1.83.6
Fixed in: 1.83.7 and later - Langflow — Langflow
Vulnerable versions: 1.8.4 and prior (CVE-2026-5027)
Fixed in: 1.9.0 and later; 1.10.0
Remediation for GTIG: AI-Era Vulnerability Discovery and Exploitation Surge
Patches
- BeyondTrust BT26-02-RS / BT26-02-PRA (RS 25.3.2+, PRA 25.1.1+)
- LiteLLM 1.83.7 and Starlette 1.0.1
- Langflow 1.9.0 / 1.10.0 (langflow-base 0.8.3)
Immediate actions
- Patch self-hosted BeyondTrust Remote Support to 25.3.2+ and Privileged Remote Access to 25.1.1+ (BT26-02 advisory) and hunt for web shells, new admin accounts and remote-access tools
- Upgrade LiteLLM to 1.83.7+ and Starlette to 1.0.1+; block or restrict /mcp-rest/test/* endpoints; rotate all upstream LLM API keys and stored credentials held by the gateway
- Upgrade Langflow to 1.10.0+ (fix in 1.9.0); disable default auto-login and remove internet exposure of Langflow instances
- Audit process trees on proxy/orchestration hosts for shells, interpreters and network tools spawned by litellm/langflow processes; check crontabs and ~/.ssh/authorized_keys for unauthorized writes
Workarounds
- Restrict BeyondTrust management interfaces and WebSocket endpoints to trusted networks
- Block egress DNS to OAST domains and monitor Cloudflare Tunnel, SimpleHelp and AnyDesk installations on appliance hosts
Longer-term hardening
- Move from volume patching to threat-intelligence-driven triage prioritizing internet-facing edge appliances and KEV-listed flaws
- Sandbox and network-isolate autonomous agent and AI orchestration workloads; never expose AI gateways or workflow builders to the internet unauthenticated
- Compress n-day patch SLAs for edge and AI middleware to days, given exploitation within about 4 days of disclosure
- Deploy pre-release AI-assisted code review to find flaws before production shipping
CVEs associated with GTIG: AI-Era Vulnerability Discovery and Exploitation Surge
CVE-2026-1731, CVE-2026-42271, CVE-2026-5027, CVE-2025-3248, CVE-2026-48710
Weaknesses (CWE) in GTIG: AI-Era Vulnerability Discovery and Exploitation Surge
CWE-78, CWE-77, CWE-22, CWE-94
Timeline of GTIG: AI-Era Vulnerability Discovery and Exploitation Surge
- Langflow CVE-2025-3248 (unauthenticated Python code injection via /api/v1/validate/code) added to the CISA Known Exploited Vulnerabilities catalog (May 2025).
- BeyondTrust automatically patches SaaS/cloud customers for CVE-2026-1731.
- BeyondTrust releases advisory BT26-02 and fixes for CVE-2026-1731 (unauthenticated OS command injection in Remote Support and Privileged Remote Access, CVSS v4 9.9).
- CISA adds CVE-2026-1731 to KEV; GTIG reports first exploitation about 4 days after disclosure and 5 additional threat clusters within 7 days.
- Unit 42 publishes analysis of CVE-2026-1731 exploitation: SparkRAT, VShell, web shells, admin account takeover and OAST DNS exfiltration.
- Langflow CVE-2026-5027 path traversal in POST /api/v2/files publicly disclosed (found by Tenable); langflow-base 0.8.3 released 2026-03-30.
- LiteLLM 1.83.7 released fixing CVE-2026-42271 (MCP test endpoint command injection); CVE published the same day.
- CVE-2026-42271 added to CISA KEV after a chained unauthenticated exploit with Starlette CVE-2026-48710 was confirmed; Qilin reported as exploiting it.
- Langflow 1.10.0 released; CVE-2026-5027 exploitation observed in the wild (honeypots see file drops), about 7,000 instances exposed.
- GTIG publishes 'Vulnerability Discovery and Exploitation Trends in the AI Era': 141 exploited vulnerabilities in Jan-Aug 2026 versus 127 in all of 2025; 2,076 cumulative AI-stack CVEs.
Sources cited for GTIG: AI-Era Vulnerability Discovery and Exploitation Surge
- Vulnerability Discovery and Exploitation Trends in the AI Era (GTIG)
- Unit 42: VShell and SparkRAT Observed in Exploitation of BeyondTrust Critical Vulnerability (CVE-2026-1731)
- Arctic Wolf: CVE-2026-1731 Unauthenticated OS Command Injection in BeyondTrust RS and PRA
- BeyondTrust Security Advisory BT26-02
- Horizon3.ai: CVE-2026-1731
- CybelAngel: Top 7 Things to Know About the LiteLLM CVE-2026-42271 Exploit
- Wiz Vulnerability Database: CVE-2026-42271
- BleepingComputer: Path traversal flaw in AI dev platform Langflow exploited in attacks
- The Hacker News: Unpatched Langflow flaw CVE-2026-5027
- Cloud Security Alliance: CVE-2026-5027 Langflow Path Traversal to Unauthenticated RCE
- CISA Known Exploited Vulnerabilities Catalog
More in vulnerability
- Cisco Catalyst SD-WAN Manager API authentication bypass zero-day (CVE-2026-76504) exploited in the wild
- CVE-2026-74864 / CVE-2026-74865: Authentication bypass in YunoHost-Apps sogo_yhn (SOGo proxy-auth trust)
- WatchGuard Fireware OS Critical Code Injection Vulnerability in BOVPN over TLS Client (CVE-2026-86131)
- Docker CopyEscape (CVE-2026-17106): docker cp / sbx cp flaw lets malicious containers overwrite host files
- Critical MikroTik RouterOS Integer Underflow Vulnerability (CVE-2026-84411) Enables Unauthenticated Remote Code Execution
Detection coverage for TL-2026-2818
As of 2026-09-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2818 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.