LiteLLM, a popular open-source gateway that sits between apps and AI model providers, has three vulnerabilities on CISA’s catalog of flaws exploited in real attacks, all added in 2026. The latest, CVE-2026-59822, let anyone with a made-up password reach the tools connected through its MCP endpoint. It’s the only MCP flaw in the catalog. Count Langflow, an AI agent builder with six entries of its own, and self-hosted AI infrastructure has nine exploited-in-the-wild flaws on the list. The pattern is clear: if you run an AI gateway or agent server on the internet, attackers treat it like any other exposed server, and a valuable one.
What’s on CISA’s list
The U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog only includes flaws with evidence of real-world exploitation. In the version we checked, dated October 8, 2026, the LiteLLM entries are:
| CVE | Added to CISA’s list | What it allowed | Login needed? | Fixed in |
|---|---|---|---|---|
| CVE-2026-42208 | May 8, 2026 | SQL injection during API key checks: read, and possibly modify, the proxy’s database, including the credentials it manages | No | 1.83.7 |
| CVE-2026-42271 | June 8, 2026 | Run any command on the host through two MCP “test connection” endpoints | Any valid key, even a low-privilege one | 1.83.7 |
| CVE-2026-59822 | September 2, 2026 | Open an authenticated MCP session with an arbitrary Bearer token, then list and call the configured MCP tools | No | 1.84.0 |
The details come from LiteLLM’s own security advisories. For the latest flaw, the advisory explains that when key validation failed, a fallback path meant for OAuth2 passthrough substituted an empty user object instead of rejecting the request. A fabricated Authorization header was enough to reach MCP tooling. CISA gave federal agencies until September 16 to fix it.
Wiz, which discovered CVE-2026-59822, adds that the command-execution flaw can be chained with a separate host-header validation bypass in Starlette (CVE-2026-48710) to reach “fully unauthenticated RCE.”

Why attackers want an AI gateway
A gateway like LiteLLM exists to centralize access. Apps send it requests, and it holds the keys for every model provider behind it. Wiz’s 90-day honeypot study names this “credential concentration”: one proxy “can hold keys for every model provider it routes to, including OpenAI, Anthropic, Azure, and Gemini,” and may also run with cloud permissions and reach internal services through MCP tool servers.
MCP raises the stakes. As we explained in MCP vs APIs vs computer use, an MCP server exposes tools that act on real systems. A gateway that brokers MCP sessions sits in front of all of them, so a bypass at the gateway is a bypass for every connected tool.
What attackers actually did
Wiz’s honeypots, decoy servers set up to watch attacks, recorded the LiteLLM flaws being used, along with tooling built for AI software specifically:
- Probing the MCP bypass with single-character tokens to find vulnerable gateways.
- Using the test endpoint to install a cryptominer, disguised as an MCP server configuration so the “test” looked successful.
- Reading the master key from the running process’s memory, because, as Wiz notes, it isn’t stored in a file a generic credential stealer would search.
- Checking which model a gateway reaches, on instances still using the default master key, according to Wiz, before deciding whether to steal the provider key or simply use up the quota.
- Hiding in plain sight, for example by staging malware in a folder named like an AI tool’s config directory, where an administrator might not look twice.
Wiz also saw “blind prompt injection” against agent frameworks with shell tools: requests crafted so that an agent with command access would run something and signal back. That’s the scenario we described in when prompt injection becomes code execution, now observed against real deployments.
If you run LiteLLM
- Upgrade to 1.84.0 or later. That covers all three exploited flaws.
- If you can’t upgrade immediately, LiteLLM’s advisory says to “disable MCP routes or block access to
/mcp/and related MCP endpoints at your reverse proxy or API gateway.” - Assume exposure means compromise. If an unpatched gateway was reachable from the internet, rotate the provider keys it held and the master key, and review what its MCP tools could access.
- Replace example or default keys with long random ones.
For any self-hosted AI infrastructure
The same advice applies to model servers, agent builders, vector databases and notebooks, and it’s ordinary web security applied to a newer kind of server:
- Don’t put admin or tool endpoints on the open internet. Keep them behind a VPN, an identity-aware proxy or an IP allowlist.
- Require authentication everywhere. Wiz notes that many AI tools ship without it, and warns that “unauthenticated on the internet” should be treated as “compromised.”
- Limit what a compromise can reach. Scope cloud permissions narrowly, restrict outbound traffic, and treat every MCP-connected service as part of the gateway’s blast radius.
- Watch for the server spawning processes. A gateway that suddenly starts a shell is a strong signal, whatever the entry point.
- Patch on release, not on schedule. Wiz observed attackers “working ahead of CVE assignment,” weaponizing fixes as soon as they appear in the code.
AI gateways were adopted to make model access simpler and cheaper to manage. That same centralization is what makes them worth attacking. They deserve the patching discipline and network isolation of any internet-facing system that holds production credentials.
CISA’s catalog (October 8, 2026 version), NVD records, LiteLLM’s advisories and Wiz’s research checked on October 10, 2026.
