CISA Puts AI Infrastructure on the KEV: Three CVEs in One Batch, Active Exploitation Already

September 4, 2026 · SPR{K}3 Research

On Tuesday, CISA added seven CVEs to its Known Exploited Vulnerabilities catalog. Three target AI infrastructure — the first KEV batch where AI components make up nearly half — and it lands in a week where Wiz's honeypots were already recording active exploitation, with cryptominers, blind prompt injection against neighboring frameworks, and, per external researchers, at least one ransomware group in the mix.

Federal remediation deadline: September 16.

The three AI CVEs

The additions — covered by The Hacker News on September 3 — sit at three layers of the AI-agent stack:

The active-exploitation piece

Wiz's September 2 honeypot telemetry supplies exploitation evidence for the LiteLLM chain:

  1. Attacker hits the LiteLLM MCP endpoint with a fabricated Bearer token; the OAuth2 passthrough fallback treats failure as success. Wiz: "an unauthenticated attacker could establish an authenticated MCP session using an arbitrary Bearer token" and "list and call configured MCP tools and access connected services exposed through MCP."
  2. They chain with CVE-2026-42271, an authenticated command-execution flaw in MCP test endpoints (LiteLLM 1.74.2–1.83.7) that spawns subprocesses as the LiteLLM host user.
  3. Payload: a Python downloader, then a cryptominer.
  4. From the same host, blind prompt-injection attempts against neighboring AI frameworks, using outbound DNS callbacks to confirm silent execution.

External researchers link the Qilin ransomware group to the same chain.

Why AI substrate keeps landing on the KEV

Third KEV addition targeting AI-agent infrastructure in six weeks:

Ray, LiteLLM, Starlette, Kestra: the tool inventory of a team standing up an AI agent this year. All rated exploited-in-the-wild by the federal government in six weeks.

The Starlette entry matters most. Starlette isn't a product; it's the framework. One host-header character bypasses authentication across every downstream ASGI service — FastAPI, vLLM, LiteLLM, every MCP server, Open WebUI. CISA KEV'd it three days after disclosure. The fix requires coordinated upgrades across every layer. Fourteen days.

What the day before said

The KEV batch landed one day after the OWASP GenAI Security Project unveiled its 2026 Top 10 for LLM Applications and the debut of its Agent Control Standard — a standards-body framework classifying the same infrastructure (LiteLLM, MCP servers, the ASGI stack behind them) as agentic-AI substrate.

Standards body names the substrate Monday. Federal agency names three CVEs on it exploited-in-the-wild Tuesday. Wiz publishes honeypot telemetry with cryptominers and ransomware attribution the same day.

What a defender does with this

The harder read: the LiteLLM primitive — a forged MCP session that lists and calls attacker-selected tools — is a category, not a bug. Every AI gateway is a routing plane; every MCP server is a tool surface. All will keep shipping CVEs. The window between "CVE assigned" and "cryptominer running" is single-digit days.

The layer that catches this isn't auth middleware — Starlette's got walked past by one character. It's behavior at the runtime boundary: an MCP session opened with a one-character token, listing new tools, spawning a subprocess that fetches a Python downloader, the host issuing outbound DNS to an unfamiliar name. Syscall- and network-layer anomalies, visible from outside the gateway, indifferent to whether the gateway thinks the caller is authenticated.

The KEV batch says the federal government has decided AI substrate is exploited-in-the-wild infrastructure. Wiz says the operators noticed a week ago. September 16 will arrive with a lot of half-upgraded stacks.

Sources


SPR{K3 is a security research operation that pairs offensive vulnerability research with runtime behavioral defense. Defend is our runtime agent. To talk about a deployment, reach us at support@sprk3.com.