Web & Cloud

LiteLLM is on CISA’s exploited list three times. Your AI gateway is now a target

Three LiteLLM flaws, including the only MCP bug in CISA's catalog, have been exploited in real attacks this year. Why AI gateways are targets, what attackers did, and how to lock yours down.

Illustration of an MCP gateway hexagon holding a ring of provider keys, with red arrows probing it from outside
Illustration: Solo Tech Pros

LiteLLM, a popular open-source gateway that sits between apps and AI model providers, has three vulnerabilities on CISA’s catalog of flaws exploited in real attacks, all added in 2026. The latest, CVE-2026-59822, let anyone with a made-up password reach the tools connected through its MCP endpoint. It’s the only MCP flaw in the catalog. Count Langflow, an AI agent builder with six entries of its own, and self-hosted AI infrastructure has nine exploited-in-the-wild flaws on the list. The pattern is clear: if you run an AI gateway or agent server on the internet, attackers treat it like any other exposed server, and a valuable one.

What’s on CISA’s list

The U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog only includes flaws with evidence of real-world exploitation. In the version we checked, dated October 8, 2026, the LiteLLM entries are:

CVE Added to CISA’s list What it allowed Login needed? Fixed in
CVE-2026-42208 May 8, 2026 SQL injection during API key checks: read, and possibly modify, the proxy’s database, including the credentials it manages No 1.83.7
CVE-2026-42271 June 8, 2026 Run any command on the host through two MCP “test connection” endpoints Any valid key, even a low-privilege one 1.83.7
CVE-2026-59822 September 2, 2026 Open an authenticated MCP session with an arbitrary Bearer token, then list and call the configured MCP tools No 1.84.0

The details come from LiteLLM’s own security advisories. For the latest flaw, the advisory explains that when key validation failed, a fallback path meant for OAuth2 passthrough substituted an empty user object instead of rejecting the request. A fabricated Authorization header was enough to reach MCP tooling. CISA gave federal agencies until September 16 to fix it.

Wiz, which discovered CVE-2026-59822, adds that the command-execution flaw can be chained with a separate host-header validation bypass in Starlette (CVE-2026-48710) to reach “fully unauthenticated RCE.”

Timeline of CISA Known Exploited Vulnerabilities entries for Langflow (six) and LiteLLM (three), with the LiteLLM MCP authentication bypass highlighted as the only MCP flaw in the catalog
Chart: Solo Tech Pros, from CISA's KEV catalog (October 8, 2026 version)

Why attackers want an AI gateway

A gateway like LiteLLM exists to centralize access. Apps send it requests, and it holds the keys for every model provider behind it. Wiz’s 90-day honeypot study names this “credential concentration”: one proxy “can hold keys for every model provider it routes to, including OpenAI, Anthropic, Azure, and Gemini,” and may also run with cloud permissions and reach internal services through MCP tool servers.

MCP raises the stakes. As we explained in MCP vs APIs vs computer use, an MCP server exposes tools that act on real systems. A gateway that brokers MCP sessions sits in front of all of them, so a bypass at the gateway is a bypass for every connected tool.

What attackers actually did

Wiz’s honeypots, decoy servers set up to watch attacks, recorded the LiteLLM flaws being used, along with tooling built for AI software specifically:

  • Probing the MCP bypass with single-character tokens to find vulnerable gateways.
  • Using the test endpoint to install a cryptominer, disguised as an MCP server configuration so the “test” looked successful.
  • Reading the master key from the running process’s memory, because, as Wiz notes, it isn’t stored in a file a generic credential stealer would search.
  • Checking which model a gateway reaches, on instances still using the default master key, according to Wiz, before deciding whether to steal the provider key or simply use up the quota.
  • Hiding in plain sight, for example by staging malware in a folder named like an AI tool’s config directory, where an administrator might not look twice.

Wiz also saw “blind prompt injection” against agent frameworks with shell tools: requests crafted so that an agent with command access would run something and signal back. That’s the scenario we described in when prompt injection becomes code execution, now observed against real deployments.

If you run LiteLLM

  1. Upgrade to 1.84.0 or later. That covers all three exploited flaws.
  2. If you can’t upgrade immediately, LiteLLM’s advisory says to “disable MCP routes or block access to /mcp/ and related MCP endpoints at your reverse proxy or API gateway.”
  3. Assume exposure means compromise. If an unpatched gateway was reachable from the internet, rotate the provider keys it held and the master key, and review what its MCP tools could access.
  4. Replace example or default keys with long random ones.

For any self-hosted AI infrastructure

The same advice applies to model servers, agent builders, vector databases and notebooks, and it’s ordinary web security applied to a newer kind of server:

  • Don’t put admin or tool endpoints on the open internet. Keep them behind a VPN, an identity-aware proxy or an IP allowlist.
  • Require authentication everywhere. Wiz notes that many AI tools ship without it, and warns that “unauthenticated on the internet” should be treated as “compromised.”
  • Limit what a compromise can reach. Scope cloud permissions narrowly, restrict outbound traffic, and treat every MCP-connected service as part of the gateway’s blast radius.
  • Watch for the server spawning processes. A gateway that suddenly starts a shell is a strong signal, whatever the entry point.
  • Patch on release, not on schedule. Wiz observed attackers “working ahead of CVE assignment,” weaponizing fixes as soon as they appear in the code.

AI gateways were adopted to make model access simpler and cheaper to manage. That same centralization is what makes them worth attacking. They deserve the patching discipline and network isolation of any internet-facing system that holds production credentials.

CISA’s catalog (October 8, 2026 version), NVD records, LiteLLM’s advisories and Wiz’s research checked on October 10, 2026.

Join the conversation

Your email address will not be published.