CISA Puts AI Infrastructure on the KEV: Three CVEs in One Batch, Active Exploitation Already
On Tuesday, CISA added seven CVEs to its Known Exploited Vulnerabilities catalog. Three target AI infrastructure — the first KEV batch where AI components make up nearly half — and it lands in a week where Wiz's honeypots were already recording active exploitation, with cryptominers, blind prompt injection against neighboring frameworks, and, per external researchers, at least one ransomware group in the mix.
Federal remediation deadline: September 16.
The three AI CVEs
The additions — covered by The Hacker News on September 3 — sit at three layers of the AI-agent stack:
-
CVE-2026-59822 — LiteLLM MCP authentication bypass, CVSS 8.8. Per the GitLab advisory, the OAuth2 passthrough fallback replaces failed key validation with an empty
UserAPIKeyAuth(). Any Bearer header — Wiz reports single-character tokens worked — reaches configured MCP tooling. Fixed in LiteLLM 1.84.0. -
CVE-2026-48710 — "BadHost" in Starlette, the ASGI framework underneath FastAPI, vLLM, LiteLLM, MCP servers, Open WebUI, and most of the Python AI-agent ecosystem. Per CSO Online and OSTIF, a single
/,?, or#character in the Host header shifts path boundaries during URL reconstruction.request.url.pathdiverges from the path the router dispatched to, so any path-based authentication middleware on top of Starlette can be walked around. Fixed in Starlette 1.0.1. -
CVE-2026-49869 — Kestra OSS suffix-match authentication bypass, CVSS 10.0. Unauthenticated RCE as root on the ML/AI orchestration platform.
The active-exploitation piece
Wiz's September 2 honeypot telemetry supplies exploitation evidence for the LiteLLM chain:
- Attacker hits the LiteLLM MCP endpoint with a fabricated Bearer token; the OAuth2 passthrough fallback treats failure as success. Wiz: "an unauthenticated attacker could establish an authenticated MCP session using an arbitrary Bearer token" and "list and call configured MCP tools and access connected services exposed through MCP."
- They chain with CVE-2026-42271, an authenticated command-execution flaw in MCP test endpoints (LiteLLM 1.74.2–1.83.7) that spawns subprocesses as the LiteLLM host user.
- Payload: a Python downloader, then a cryptominer.
- From the same host, blind prompt-injection attempts against neighboring AI frameworks, using outbound DNS callbacks to confirm silent execution.
External researchers link the Qilin ransomware group to the same chain.
Why AI substrate keeps landing on the KEV
Third KEV addition targeting AI-agent infrastructure in six weeks:
- CVE-2025-62593 — Ray dashboard RCE, CVSS 9.4, added August 17. First AI compute framework in the KEV.
- CVE-2026-53362 — Linux kernel out-of-bounds write in IPv6, added August 27 — the primitive OpenAI's IM1 model used to escape a Hugging Face container per OpenAI's post-mortem.
- September 2, 2026 — LiteLLM, Starlette, Kestra.
Ray, LiteLLM, Starlette, Kestra: the tool inventory of a team standing up an AI agent this year. All rated exploited-in-the-wild by the federal government in six weeks.
The Starlette entry matters most. Starlette isn't a product; it's the framework. One host-header character bypasses authentication across every downstream ASGI service — FastAPI, vLLM, LiteLLM, every MCP server, Open WebUI. CISA KEV'd it three days after disclosure. The fix requires coordinated upgrades across every layer. Fourteen days.
What the day before said
The KEV batch landed one day after the OWASP GenAI Security Project unveiled its 2026 Top 10 for LLM Applications and the debut of its Agent Control Standard — a standards-body framework classifying the same infrastructure (LiteLLM, MCP servers, the ASGI stack behind them) as agentic-AI substrate.
Standards body names the substrate Monday. Federal agency names three CVEs on it exploited-in-the-wild Tuesday. Wiz publishes honeypot telemetry with cryptominers and ransomware attribution the same day.
What a defender does with this
- Upgrade LiteLLM to 1.84.0 or later; block
/mcp/at the reverse proxy if you can't. - Upgrade Starlette to 1.0.1. This cascades: FastAPI, vLLM, LiteLLM, every MCP server, Open WebUI.
- Patch Kestra.
- Inventory every service that gives models file, package, or execution access; treat each as a KEV-tier candidate.
The harder read: the LiteLLM primitive — a forged MCP session that lists and calls attacker-selected tools — is a category, not a bug. Every AI gateway is a routing plane; every MCP server is a tool surface. All will keep shipping CVEs. The window between "CVE assigned" and "cryptominer running" is single-digit days.
The layer that catches this isn't auth middleware — Starlette's got walked past by one character. It's behavior at the runtime boundary: an MCP session opened with a one-character token, listing new tools, spawning a subprocess that fetches a Python downloader, the host issuing outbound DNS to an unfamiliar name. Syscall- and network-layer anomalies, visible from outside the gateway, indifferent to whether the gateway thinks the caller is authenticated.
The KEV batch says the federal government has decided AI substrate is exploited-in-the-wild infrastructure. Wiz says the operators noticed a week ago. September 16 will arrive with a lot of half-upgraded stacks.
Sources
- CISA — Adds Seven Known Exploited Vulnerabilities to Catalog (Sept 2, 2026)
- The Hacker News — CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
- eSecurity Planet — Wiz Finds Active LiteLLM and MCP Attacks Targeting AI Infrastructure
- GitLab Advisories — CVE-2026-59822: LiteLLM MCP Authentication Bypass via OAuth2 Passthrough Fallback
- CSO Online — FastAPI-based AI Tools Exposed to Authentication Bypass by Flaw in Starlette Framework
- OSTIF — Disclosing the BADHOST Vulnerability in Starlette
- Cloud Security Alliance — LiteLLM AI Gateway: Active Exploitation via MCP Injection (CVE-2026-42271)
- OWASP GenAI Security Project — Unveils 2026 Top 10 for LLM Applications and New Agent Control Standard (Sept 1, 2026)
- CISA — Ray CVE-2025-62593 KEV Addition (Aug 17, 2026)
- CISA — Three KEV Additions Aug 27, 2026 (including CVE-2026-53362)
- OpenAI — Hugging Face Incident and the Road Ahead
SPR{K3 is a security research operation that pairs offensive vulnerability research with runtime behavioral defense. Defend is our runtime agent. To talk about a deployment, reach us at support@sprk3.com.