CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Called exploited the same day it was disclosed.
Measured from the CVE publication date to the earliest of 3 KEV catalogues that list it.
The life of this vulnerability
- CVE published
- First KEV listingsame day
- Last KEV listing56d
- Last sightingsame day
Gaps are compressed to equal steps. The elapsed time is printed under each.
Which catalogues call it exploited
- CISA KEVUS federallisted Sep 2, 2026
- EUVDENISA, European Unionlisted Sep 2, 2026
- VulnCheck KEVcommercial researchlisted Jul 8, 2026
- CIRCLaggregator, mirrors the abovelisted Sep 2, 2026, not counted
3 catalogues list it. CIRCL aggregates the others and is shown but not counted.
Public exploitation evidence
- reported exploitationprevidian.com/CVE-2026-59822
- reported exploitationwww.cisa.gov/sites/default/files/feeds/known_exploited_vulne
- reported exploitationwww.wiz.io/blog/ai-infrastructure-honeypot
- reported exploitationwww.linkedin.com/posts/yaarashriki_cve-2026-59821-cve-2026-5
- reported exploitationeuvd.enisa.europa.eu/enisa/EUVD-2026-42359
5 public reports collected from VulnCheck and CIRCL, first on Jul 8, 2026. Each links to its original source. We have not verified them.
Description
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAuth2 passthrough fallback path that replaced failed LiteLLM key validation with an empty UserAPIKeyAuth() object, allowing requests to reach MCP tooling without a valid LiteLLM key. This issue is fixed in version 1.84.0.
Required action (CISA)
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.