The latest in AI, every dayAI News
← AI News

September 7, 2026 · CISA / The Hacker News

CISA Adds Actively Exploited Critical Authentication Bypass in LiteLLM MCP Endpoint to Known Exploited Vulnerabilities Catalog

My take: CISA confirmed on September 2 that real-world attackers are actively exploiting a critical flaw in LiteLLM, one of the most widely used tools for connecting language models to applications, databases, and cloud services.

The vulnerability (CVE-2026-59822, CVSS score 8.8) lives in the Model Context Protocol (MCP) endpoint. An attacker without valid credentials can fabricate an authorization header to trigger an OAuth2 fallback path that replaces key validation with an empty object, creating an authenticated session with full access to configured MCP tools. From there, they can potentially reach databases, cloud services, and internal infrastructure. The fix is to update to LiteLLM version 1.84.0 or later.

For anyone building with AI, the lesson is not new: integrations between AI tools and your systems are not secure by default. Keeping dependencies updated and auditing MCP permissions are part of the work, not optional tasks.

When did you last audit the versions of the AI tools running in your production stack?

Read at the source: CISA / The Hacker News ↗

Want to use these tools? See the unbiased reviews or back to the news.