CISA Adds LiteLLM and Kestra AI Infrastructure Flaws to Exploited Vulnerabilities List
The US Cybersecurity and Infrastructure Security Agency (CISA) added vulnerabilities in LiteLLM and Kestra to its Known Exploited Vulnerabilities catalog on September 2, 2026, marking the first time AI infrastructure components have appeared alongside traditional software flaws on the list. LiteLLM, an AI gateway, carries an improper authentication flaw rated CVSS 8.8, while Kestra, a workflow orchestration platform, has an OS command injection vulnerability rated a critical CVSS 10.0. A ZoomEye internet scan conducted on September 19, 2026, found over 34,000 internet-facing LiteLLM instances and 126 Kestra deployments, highlighting meaningful public exposure. Because these platforms routinely store sensitive credentials such as model provider API keys and database tokens, a successful exploit risks large-scale credential theft rather than mere service disruption. Security researchers are urging organizations to take these AI services offline from public internet access, apply patches immediately, and rotate any potentially exposed credentials.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in