CVE-2026-33634Active Exploitation(aquasec / litellm)

HIGHCVSS 8.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 14 mentions and remains active

Immediate actions

  • Patch aquasec litellm systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to credential-stealing malware, and replace all 7 tags in `aquasecurity/setup-trivy` with malicious commits. This incident is a continuation of the supply chain attack that began in late February 2026. Following the initial disclosure on March 1, credential rotation was performed but was not atomic (not all credentials were revoked simultaneously). The attacker could have use a valid token to exfiltrate newly rotated secrets during the rotation window (which lasted a few days). This could have allowed the attacker to retain access and execute the March 19 attack. Affected components include the `aquasecurity/trivy` Go / Container image version 0.69.4, the `aquasecurity/trivy-action` GitHub Action versions 0.0.1 – 0.34.2 (76/77), and the`aquasecurity/setup-trivy` GitHub Action versions 0.2.0 – 0.2.6, prior to the recreation of 0.2.6 with a safe commit. Known safe versions include versions 0.69.2 and 0.69.3 of the Trivy binary, version 0.35.0 of trivy-action, and version 0.2.6 of setup-trivy. Additionally, take other mitigations to ensure the safety of secrets. If there is any possibility that a compromised version ran in one's environment, all secrets accessible to affected pipelines must be treated as exposed and rotated immediately. Check whether one's organization pulled or executed Trivy v0.69.4 from any source. Remove any affected artifacts immediately. Review all workflows using `aquasecurity/trivy-action` or `aquasecurity/setup-trivy`. Those who referenced a version tag rather than a full commit SHA should check workflow run logs from March 19–20, 2026 for signs of compromise. Look for repositories named `tpcp-docs` in one's GitHub organization. The presence of such a repository may indicate that the fallback exfiltration mechanism was triggered and secrets were successfully stolen. Pin GitHub Actions to full, immutable commit SHA hashes, don't use mutable version tags.

7.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-04-09. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-506

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • litellm
  • setup-trivy
  • telnyx
  • trivy

Threat summary

  • Active exploitation appears in 47 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 75 mentions across 30 observed days

What's happening

  • Active exploitation reported across 47 signals
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 13 signals
  • Technical details provided in 31 signals
  • Disclosure: 15 classified signals
  • General: 12 classified signals
  • Peaked 25d ago at 14 mentions (2026-03-27); latest day: 1
  • 75 total mentions across 30 days

Affected systems

Products
litellmsetup-trivytelnyxtrivytrivy_action

5 versions affected across 5 products

Deep dive

Activity timeline75 mentions / 30d
0471114Mentions · 2026-03-23: 1Mentions · 2026-03-24: 4Mentions · 2026-03-25: 4Mentions · 2026-03-26: 7Mentions · 2026-03-27: 14Mentions · 2026-03-28: 5Mentions · 2026-03-29: 4Mentions · 2026-03-30: 3Mentions · 2026-03-31: 2Mentions · 2026-04-01: 2Mentions · 2026-04-02: 1Mentions · 2026-04-03: 4Mentions · 2026-04-06: 1Mentions · 2026-04-09: 1Mentions · 2026-04-10: 1Mentions · 2026-04-12: 1Mentions · 2026-04-13: 1Mentions · 2026-04-15: 1Mentions · 2026-04-20: 1Mentions · 2026-04-22: 1Mentions · 2026-04-24: 2Mentions · 2026-04-28: 1Mentions · 2026-05-12: 4Mentions · 2026-05-13: 1Mentions · 2026-05-15: 2Mentions · 2026-05-28: 1Mentions · 2026-06-19: 1Mentions · 2026-06-23: 2Mentions · 2026-07-02: 1Mentions · 2026-08-27: 1PoC Mentioned / Linked · 2026-03-27: 1PoC Mentioned / Linked · 2026-05-12: 1PoC Mentioned / Linked · 2026-05-15: 1Active Exploitation · 2026-03-23: 1Active Exploitation · 2026-03-24: 3Active Exploitation · 2026-03-25: 4Active Exploitation · 2026-03-26: 3Active Exploitation · 2026-03-27: 13Active Exploitation · 2026-03-28: 3Active Exploitation · 2026-03-29: 1Active Exploitation · 2026-03-30: 1Active Exploitation · 2026-03-31: 2Active Exploitation · 2026-04-01: 1Active Exploitation · 2026-04-03: 3Active Exploitation · 2026-04-06: 1Active Exploitation · 2026-04-12: 1Active Exploitation · 2026-04-13: 1Active Exploitation · 2026-04-15: 1Active Exploitation · 2026-04-22: 1Active Exploitation · 2026-04-24: 1Active Exploitation · 2026-04-28: 1Active Exploitation · 2026-05-13: 1Active Exploitation · 2026-05-15: 1Active Exploitation · 2026-06-19: 1Active Exploitation · 2026-07-02: 1Active Exploitation · 2026-08-27: 1Patch / Workaround · 2026-03-24: 1Patch / Workaround · 2026-03-25: 1Patch / Workaround · 2026-03-26: 1Patch / Workaround · 2026-03-27: 5Patch / Workaround · 2026-03-28: 1Patch / Workaround · 2026-04-01: 1Patch / Workaround · 2026-04-03: 1Patch / Workaround · 2026-04-24: 1Patch / Workaround · 2026-05-12: 1Technical Details · 2026-03-23: 1Technical Details · 2026-03-25: 1Technical Details · 2026-03-26: 3Technical Details · 2026-03-27: 7Technical Details · 2026-03-28: 3Technical Details · 2026-03-30: 2Technical Details · 2026-03-31: 2Technical Details · 2026-04-02: 1Technical Details · 2026-04-24: 2Technical Details · 2026-05-12: 3Technical Details · 2026-05-13: 1Technical Details · 2026-05-28: 1Technical Details · 2026-06-19: 1Technical Details · 2026-06-23: 2Technical Details · 2026-07-02: 103-2303-2603-2904-0104-0604-1204-2004-2805-1506-2308-27
Signal classification4 categories
Active Exploitation
4458.7%
Disclosure
1520.0%
General
1216.0%
Patch
45.3%
Referenced assets44 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-231
Active Exploitation1
2026-03-244
Active Exploitation2General1Patch1
2026-03-254
Active Exploitation4
2026-03-267
Active Exploitation3Disclosure2General1Patch1
2026-03-2714
Active Exploitation13Patch1
2026-03-285
Active Exploitation3Disclosure1General1
2026-03-294
Active Exploitation1Disclosure1General2
2026-03-303
Active Exploitation1Disclosure1General1
2026-03-312
Active Exploitation2
2026-04-012
Active Exploitation1General1
2026-04-021
Disclosure1
2026-04-034
Active Exploitation2Disclosure1Patch1
2026-04-061
General1
2026-04-091
General1
2026-04-101
Disclosure1
2026-04-121
Active Exploitation1
2026-04-131
Active Exploitation1
2026-04-151
Active Exploitation1
2026-04-201
General1
2026-04-221
Active Exploitation1
2026-04-242
Active Exploitation1Disclosure1
2026-04-281
Active Exploitation1
2026-05-124
Disclosure3General1
2026-05-131
Active Exploitation1
2026-05-152
Active Exploitation1General1
2026-05-281
Disclosure1
2026-06-191
Active Exploitation1
2026-06-232
Disclosure2
2026-07-021
Active Exploitation1
2026-08-271
Active Exploitation1
Full discourse20 posts
  • Rami McCarthy@ramimacisabird
    General

    Aqua postmortem: https://github.com/aquasecurity/trivy/discussions/10462 ownCloud Blog: https://owncloud.com/security-advisories/security-notice-impact-of-cve-2026-33634-on-owncloud-build-infrastructure/ Both now on https://ramimac.me/teampcp/, as well as the links to review my analysis on blast radius!

    Post summary

    The text references an Aqua postmortem, an ownCloud security advisory, and a review page, but does not provide detailed technical information, PoC, exploit, or patch details.

    07029203.1K
    4.9K followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added Aqua Security Trivy embedded malicious code vulnerability CVE-2026-33634 to our Known Exploited Vulnerabilities Catalog. Visit https://go.dhs.gov/Z3Q for more information. #Cybersecurity #InfoSec https://t.co/MU0cSf49X7

    Post summary

    The tweet announces that CVE-2026-33634 has been added to the DHS Known Exploited Vulnerabilities Catalog and links for more information, but provides no technical details, patches, or exploit code.

    21522364.3K
    293.4K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(3/26追加) 🛡️No.1554 CVE-2026-33634 Aqua Security Trivy Embedded Malicious Code Vulnerability ==================================== ✅概要 ・深刻度:緊急🔥 9.4 (CVSS Base) / NVD ・種別:埋め込まれた悪意あるコード (CWE-506) ・CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Aqua Security の脆弱性スキャナ「Trivy」において、公式リリースおよび関連 GitHub Actions が侵害され、悪意あるコードが埋め込まれたサプライチェーン攻撃が発生した脆弱性。 攻撃者は CI/CD 資格情報を奪取し、 ・Trivy v0.69.4 の悪意あるリリース公開 ・ `trivy-action` の大部分のタグを改ざん ・`setup-trivy` のタグを不正コミットに置換 を行い、CI/CD 環境で実行されるコードに認証情報窃取機能を混入させたもの。 ✅ChatGPTによる脆弱性評価 ・国内影響度判定:高 ・悪用難易度:低 ✅攻撃前提条件 ・影響バージョン(Trivy v0.69.4 や改ざんされた GitHub Actions)を使用していること ・CI/CD パイプライン内で Trivy が実行されること ・外部リポジトリからアクションやイメージを取得していること ✅悪用時影響 ・CI/CD 環境の完全侵害 ・トークン、SSH鍵、クラウド認証情報の窃取 ・パイプライン経由での横展開 ・サプライチェーン全体への波及 ✅悪用事例等に関する公開情報 ・PoC/Exploit:不要(実際の攻撃コードが公式リリースに混入) ・ITW:あり(実際のサプライチェーン侵害として確認) この脆弱性は、実際に CI/CD パイプラインを標的とした攻撃が発生したインシデントそのもので、侵害されたリリースが数時間〜十数時間配布されていたことが確認された。 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-33634 https://github.com/advisories/GHSA-69fq-xp46-6x23 https://cvereports.com/reports/CVE-2026-33634 https://www.cisa.gov/news-events/alerts/2026/03/26/cisa-adds-one-known-exploited-vulnerability-catalog #vulnerability

    Post summary

    CVE‑2026‑33634, an Aqua Trivy vulnerability, was actively exploited in supply‑chain attacks that injected malicious code into official releases; the incident was confirmed by CISA and no mitigation is mentioned.

    0101025.7K
    42.9K followersView on X
  • Sentrinus@sentrinus
    Active Exploitation

    Your security scanner just became the weapon. CVE-2026-33634 (CVSS 9.4): Aqua Trivy was compromised. Every scan silently stole your AWS keys, SSH creds, and Kubernetes tokens. 🔴 https://t.co/J55PY7d672

    Post summary

    The tweet reports that CVE-2026-33634, affecting Aqua Trivy, is actively exploited, silently exfiltrating AWS keys, SSH credentials, and Kubernetes tokens.

    11120234
    8 followersView on X
  • Virendra Patel@V1rendra_
    Disclosure

    Headline Hook: " Open-Source Supply Chain Attacks Explode: Trivy, LiteLLM, Axios Hit Hard!" Key Facts: TeamPCP compromised Trivy (CVE-2026-33634), LiteLLM backdoor (v1.82.7/8), leading to Mercor 4TB breach. Impact: Pinned deps steal creds from Cl/CD & dev machines. Security tools now attack vectors! Call to Action: "Audit deps, verify releases, patch NOW! #CyberSec #OpenSource" Engagement: End with question: "Hit by this? Share your story below!"

    Post summary

    This post announces the exploitation of Trivy CVE-2026-33634 via supply‑chain attacks and urges users to audit and patch dependencies, but does not provide technical details, patches, or exploit code.

    00040340
    1.4K followersView on X
  • Ross Lazer@rosslazer
    General

    Add Kelp DAO to the supply chain pile-up. The last ~30 days: - AppsFlyer Web SDK (crypto wallet swap) - Trivy (TeamPCP, CVE-2026-33634) - European Commission cloud (via Trivy) - Checkmarx KICS (TeamPCP) - LiteLLM (TeamPCP, ~36% of cloud envs) - Telnyx Python SDK (TeamPCP) - Axios npm (DPRK / Sapphire Sleet) - Trust Wallet extension (Shai-Hulud, $8.5M) - Counterfeit Ledger wallets ($9.5M) - Context[.]ai → Vercel (ShinyHunters, OAuth pivot) - Kelp DAO (this one) This is a wakeup call to audit your dependencies, and your dependencies' dependencies.

    Post summary

    The post lists recent supply‑chain vulnerability findings, including a CVE‑2026‑33634 in Trivy, and urges organizations to audit their software dependencies and sub‑dependencies.

    00120898
    895 followersView on X
  • Krishna Kumar@krishnapro_
    Disclosure

    AI Infrastructure is under fire. we've seen a triple vulnerability disclosure for LangChain, LangGraph, and LiteLLM (CVE-2026-33634). If you're building "AI-Native" backends, your attack surface just shifted from your DB to your Prompt Orchestration layer. Time to audit your serialization logic - fast.

    Post summary

    The post announces a triple vulnerability disclosure (CVE-2026-33634) affecting LangChain, LangGraph, and LiteLLM, urging teams building AI-native backends to audit their serialization logic.

    01011112
    1.4K followersView on X
  • SOCRadar®@socradar
    Active Exploitation

    Tracked as CVE-2026-33634. Added to CISA KEV on 26 March 2026. SOCRadar tracks this actor as UNC6780, PCPcat, ShellForce, DeadCatx3. Other campaigns tied to the same group in 2026: Checkmarx KICS, Telnyx Python SDK, Bitwarden CLI, TanStack, Mistral AI.

    Post summary

    CVE-2026-33634 has been added to the CISA Known Exploited Vulnerabilities list, indicating it is actively exploited in the wild, while the notice contains no PoC, exploit code, patch information, or technical details.

    20000163
    6.6K followersView on X
  • ThreatAft@ThreatAft
    Disclosure

    🚨 Third time’s the breach. TeamPCP backdoored the Checkmarx Jenkins AST plugin (CVE-2026-33634, CVSS 9.4) — version 2026.5.09. Stolen credentials from the March Trivy hack were never fully rotated. 🔗 https://threataft.com/articles/teampcp-checkmarx-jenkins-plugin-supply-chain-attack #CyberSecurity #supplychain #Jenkins #TeamPCP

    Post summary

    TeamPCP disclosed a backdoor in the Checkmarx Jenkins AST plugin (CVE-2026-33634, CVSS 9.4), noting that stolen credentials from a prior Trivy hack were not fully rotated and linking to further details.

    00011149
    24 followersView on X
  • Orca Security@orcasec
    Active Exploitation

    🚨 CVE-2026-33634 (CVSS 9.4): The TeamPCP campaign is actively exploiting Checkmarx GitHub Actions to steal CI/CD secrets — no auth required. Full breakdown + remediation guide 👇 https://orca.security/resources/blog/checkmarx-supply-chain-compromise-ci-cd-secrets/?utm_source=twitter&utm_medium=organic+social&utm_campaign=orca+blog https://t.co/cdy80viuuB

    Post summary

    CVE-2026-33634 is being actively exploited by the TeamPCP campaign to steal CI/CD secrets from Checkmarx GitHub Actions without authentication, and a remediation guide is provided through the linked resource.

    01010178
    4.8K followersView on X
  • AgentCost In@agentcostin
    General

    After the LiteLLM supply chain attack (CVE-2026-33634), AgentCost was unaffected. The pricing database for 2,610+ models is vendored locally.

    Post summary

    The statement notes that AgentCost was unaffected by a published supply chain attack involving CVE-2026-33634, with no additional technical or mitigation details provided.

    1001036
    2 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2020-5902 2 - CVE-2026-33634 3 - CVE-2025-31277 4 - CVE-2026-20643 5 - CVE-2025-53521 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post merely enumerates trending CVE identifiers without providing any details on exploitation, patches, or technical aspects.

    00011395
    1.7K followersView on X
  • The Cyber Security Hub™@TheCyberSecHub
    Active Exploitation

    CISA sounds alarm on Langflow RCE, Trivy supply chain compromise after rapid exploitation https://www.helpnetsecurity.com/2026/03/27/cve-2026-33017-cve-2026-33634-exploited/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    CISA issues an alarm that CVE‑2026‑33017 (Langflow RCE) and CVE‑2026‑33634 (Trivy supply chain) are actively exploited, highlighting urgent vendor action.

    01010470
    193.8K followersView on X
  • Help Net Security@helpnetsecurity
    Active Exploitation

    CISA sounds alarm on Langflow RCE, Trivy supply chain compromise after rapid exploitation - https://www.helpnetsecurity.com/2026/03/27/cve-2026-33017-cve-2026-33634-exploited/ - @CISACyber @CISAgov @langflow_ai @AquaSecTeam #SupplyChainCompromise #Vulnerability #Cybersecurity #CybersecurityNews

    Post summary

    The statement highlights that CISA is warning about rapid exploitation of Langflow RCE and associated supply chain vulnerabilities, indicating active real‑world attacks, but provides no direct exploit code, patch, or PoC.

    10010362
    60.0K followersView on X
  • Pay MPs Universal Credit@angryaboutbikes
    General

    Hate it when you install a security scanner to warn you of hacked software stealing your shit then it gets hacked and steals your shit https://www.tenable.com/cve/CVE-2026-33634

    Post summary

    The tweet only expresses frustration and links to the CVE page, offering no technical or exploit information.

    00020216
    3.5K followersView on X
  • CVE@CVEnew
    Active Exploitation

    CVE-2026-33634 Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version … https://www.cve.org/CVERecord?id=CVE-2026-33634

    Post summary

    A threat actor leveraged compromised credentials to push a malicious Trivy v0.69.4 release across many versions, demonstrating active exploitation of CVE‑2026‑33634.

    00011383
    56.8K followersView on X
  • GoCocoaAI@GoCocoaAI
    Active Exploitation

    Sources behind this thread: CSA Research Note — LLMjacking Evolved (CVE-2026-7482, CVE-2026-33634): https://labs.cloudsecurityalliance.org/research/csa-research-note-llmjacking-evolved-offensive-agentic-20260/ The Register — SharePoint RCE KEV confirmation (CISA, active exploitation): https://www.theregister.com/security/2026/07/02/microsoft-said-exploitation-was-less-likely-but-cisa-just-added-sharepoint-rce-to-kev-list/5265886 The Hacker News — ThreatsDay digest (AI compute hijacking, Apple Mail flaw, BlueHammer): https://thehackernews.com/2026/07/threatsday-ai-compute-hijacking-apple.html Oracle EBS pre-PoC exploitation, Medtronic/ShinyHunters disclosure, and FortiBleed/INC+Lynx crossover via The Register (July 2, 2026). BlueHammer carries no confirmed registry entry as of publication — assessed at medium confidence, pattern analysis only.

    Post summary

    The passage highlights multiple CVEs, most notably a SharePoint RCE that has been confirmed as actively exploited by CISA, while also citing other vulnerabilities discussed in research notes without indicating available patches or exploit tools.

    0001075
    37 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-33634 · 2026.5.09 → 9.4 CVE-2026-33634: TeamPCP Backdoors Checkmarx Jenkins Plugin — CRITICAL RCE in DevOps Pipelines

    Post summary

    The text announces CVE-2026-33634, a critical remote code execution flaw in the TeamPCP Backdoors Checkmarx Jenkins Plugin affecting DevOps pipelines, but provides no information on exploits, patches, or active use.

    1000084
    295 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-33634: TeamPCP Backdoors Checkmarx Jenkins Plugin — CRITICAL RCE in DevOps Pipelines On May 10-12, 2026, TeamPCP gained unauthorized access to Checkmarx's Jenkins AST plugin GitHub repository and published a trojanized release.

    Post summary

    The text announces a critical remote code execution vulnerability (CVE‑2026‑33634) in Checkmarx’s Jenkins AST plugin, caused by a trojanized release identified during May 2026.

    1000060
    295 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    TL;DR TeamPCP backdoored the Checkmarx Jenkins AST plugin (CVE-2026-33634, CVSS 9.4) and published it to the Jenkins Marketplace as version 2026.5.09. The malware harvests CI runner secrets (GitHub tokens, AWS/GCP/Azure credentials, SSH keys) and exfiltrates them to…

    Post summary

    A malicious Checkmarx Jenkins AST plugin (CVE‑2026‑33634) was published to the Jenkins Marketplace, actively exfiltrating CI secrets; no patch or mitigation notice is provided.

    1000064
    294 followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
Appaquasecsetup-trivy---
Appaquasectrivy0.69.4go-
Appaquasectrivy_action---
Applitellmlitellm1.82.7--
Applitellmlitellm1.82.8--
Apptelnyxtelnyx4.87.1python-
Apptelnyxtelnyx4.87.2python-

Explore more