CISA adds first AI agent flaw to its must-patch list
LiteLLM CVE-2026-59822 lets attackers open authenticated MCP sessions with any token — the first exploited AI agent infrastructure bug in CISA's KEV.
By Priya Nair · Published · Updated · 4 min read

On September 2, CISA added CVE-2026-59822, a flaw in the open-source AI proxy LiteLLM, to its Known Exploited Vulnerabilities catalog — the first confirmed, actively exploited bug in production AI agent infrastructure to make the list, Tech Insider reports.
What the flaw does
LiteLLM routes traffic between apps and large language models. The bug is in its Model Context Protocol (MCP) Streamable HTTP endpoint. An unauthenticated attacker can open a fully authenticated MCP session using any bearer token at all.
It is rated high severity (CVSS 4.0 score of 8.8).
Why it matters
MCP is the standard way AI agents connect to tools, databases and business workflows. A hijacked MCP session can let an outsider make an organization's AI agents run tools, read data or trigger actions on their behalf. As companies give agents more access, these connectors become as valuable to attackers as VPNs and email servers.
Earlier AI framework warnings
It is not the first warning. In July, CISA ordered federal agencies to patch an exploited authorization flaw in Langflow, the third Langflow bug it had flagged, Anavem reported. Attackers were stealing cloud and AI service keys.
What teams running AI agents should do
- Update LiteLLM to a fixed version now.
- Keep MCP endpoints off the public internet.
- Give each agent only the tools and data it needs.
- Rotate model API keys and cloud credentials if you suspect exposure.

