CISA Lists LiteLLM and Kestra Flaws, but Microsoft Saw Different CVEs
Security / news
CISA Lists LiteLLM and Kestra Flaws, but Microsoft Saw Different CVEs
The LiteLLM bug on the exploited list (fixed in 1.84.0) is not the one in Microsoft’s incident report, and published scores for it disagree.

CISA added three pieces of AI-stack software to its Known Exploited Vulnerabilities catalog on September 2: BerriAI's LiteLLM (CVE-2026-59822), the Kestra workflow engine (CVE-2026-49869) and the Starlette web framework (CVE-2026-48710). The attacker needs only network access to an exposed instance, and in LiteLLM's case no credentials at all. The fix for LiteLLM is version 1.84.0.
The CISA alert lists seven flaws in total, including SonicWall SMA1000, JFrog Artifactory and Sangoma Switchvox. The three AI-stack entries are the ones with a matching field report: Microsoft Security Research published observed intrusions into a LiteLLM gateway, a RAGFlow deployment and a Kestra environment on August 26, a week before the catalogue entry.

The CVE on the list is not the one Microsoft saw
The two do not line up, and the difference matters for anyone triaging. Microsoft's LiteLLM incident involved CVE-2026-42271, an authenticated command-execution flaw in MCP stdio test endpoints, together with CVE-2026-48710 in Starlette, a host-header validation bypass. It does not name CVE-2026-59822.
CVE-2026-59822 is a separate bug. According to the GitLab advisory, LiteLLM's MCP Streamable HTTP endpoint has an OAuth2 passthrough meant for upstream MCP servers. When key validation fails, it falls back to an empty UserAPIKeyAuth() object instead of rejecting the request, so an arbitrary Bearer token opens an authenticated MCP session. Every version before 1.84.0 is affected.
The published scores disagree. The Hacker News reports CVSS 8.8 for CVE-2026-59822; the GitLab advisory says 8.2. Neither score overstates the precondition problem: the attacker needs no privileges and no user interaction, and what they reach is whatever MCP tools and connected services the gateway exposes.
What the attackers did after getting in
Microsoft describes three separate intrusions with one goal. On LiteLLM, the payload read the gateway process environment and filtered for credential values including model-provider API keys, then fingerprinted the host and killed competing miners before starting XMRig. It also reached an Azure Database for PostgreSQL instance and persisted through SSH keys, cron entries and immutable file attributes.
On RAGFlow, attackers ran SSRF-style reconnaissance and, days later, code execution. They placed a Python hook in the tenant LLM configuration flow, so every provider key entered after infection was captured. On Kestra, they ran shells from workflows, probed Docker and deployed XMRig.
| Product | CVEs Microsoft names | CISA KEV entry (Sept 2) |
|---|---|---|
| LiteLLM | CVE-2026-42271, CVE-2026-48710 | CVE-2026-59822 (and CVE-2026-48710 via Starlette) |
| Kestra | CVE-2026-49869 | CVE-2026-49869 |
| RAGFlow | CVE-2026-45312, CVE-2026-28797, CVE-2026-24770, CVE-2025-68700, CVE-2025-69286 | None listed |
Labels also differ. Microsoft calls the Kestra bug an authentication bypass; CISA lists CVE-2026-49869 as OS command injection. The Hacker News rates it CVSS 10.0 and says it allows workflow execution without credentials, which would make both labels partly right. The same outlet rates Starlette's CVE-2026-48710 at 6.5, which is moderate on its face but sits underneath the LiteLLM chain.
Deadlines and what to do
The Hacker News reports that most of the seven flaws carry a federal patch deadline of September 5, while the Starlette and LiteLLM entries run to September 16. CISA's binding directive BOD 26-04 applies to federal civilian agencies only. Everyone else is on their own clock.
Microsoft's advice is to treat AI gateways as Tier-0 secret stores: issue per-team virtual keys with spend limits rather than sharing a master key, run the proxy under a dedicated low-privilege database account, and allow only required outbound destinations. If a LiteLLM instance below 1.84.0 was reachable from the internet, rotate every provider key it held, because Microsoft's own write-up shows the first thing the payload did was read them.
The question of what an agent runtime can reach is also the subject of our report on NVIDIA's OpenShell agent sandbox. For how CISA's catalogue has handled other exploited flaws this month, see our piece on three Linux kernel CVEs and the score gap.
Sources
More in Security
- 01Fortinet FortiMail Path-Traversal Flaw Exploited Before Fixes ShipCVE-2026-104286 lets an unauthenticated attacker write files to a FortiMail appliance, and one analyst reading of Fortinet's advisory says the patched builds may not be downloadable yet.
- 02Citrix Confirms Two NetScaler Zero-Days Exploited Since Early SeptemberPalo Alto Networks' Unit 42 traces exploitation of CVE-2026-88771 and CVE-2026-88772 to Sept. 4, 23 days before Citrix published its bulletin, and says patching will not evict an attacker who is already inside.
- 03Cisco SD-WAN Manager Auth Bypass Exploited, With No WorkaroundCVE-2026-76504 gives an unauthenticated attacker admin access to the Catalyst SD-WAN Manager API, and Cisco's only advice besides patching is to keep the interface off untrusted networks.
- 04Three Exploited Edge Flaws Test CISA's Three-Day Patch DeadlineCitrix, Cisco and Fortinet appliances landed in the Known Exploited Vulnerabilities catalog within five days, and BOD 26-04 asks agencies to collect evidence before they patch any of them.