Skip to content
Unlisted Report logoUnlisted ReportSubscribe
AI Security

CISA adds first AI agent flaw to its must-patch list

LiteLLM CVE-2026-59822 lets attackers open authenticated MCP sessions with any token — the first exploited AI agent infrastructure bug in CISA's KEV.

By · Published · Updated · 4 min read

Abstract image for the LiteLLM AI agent vulnerability

On September 2, CISA added CVE-2026-59822, a flaw in the open-source AI proxy LiteLLM, to its Known Exploited Vulnerabilities catalog — the first confirmed, actively exploited bug in production AI agent infrastructure to make the list, Tech Insider reports.

What the flaw does

LiteLLM routes traffic between apps and large language models. The bug is in its Model Context Protocol (MCP) Streamable HTTP endpoint. An unauthenticated attacker can open a fully authenticated MCP session using any bearer token at all.

It is rated high severity (CVSS 4.0 score of 8.8).

Why it matters

MCP is the standard way AI agents connect to tools, databases and business workflows. A hijacked MCP session can let an outsider make an organization's AI agents run tools, read data or trigger actions on their behalf. As companies give agents more access, these connectors become as valuable to attackers as VPNs and email servers.

Earlier AI framework warnings

It is not the first warning. In July, CISA ordered federal agencies to patch an exploited authorization flaw in Langflow, the third Langflow bug it had flagged, Anavem reported. Attackers were stealing cloud and AI service keys.

What teams running AI agents should do

  • Update LiteLLM to a fixed version now.
  • Keep MCP endpoints off the public internet.
  • Give each agent only the tools and data it needs.
  • Rotate model API keys and cloud credentials if you suspect exposure.

Sources

Read next