daily cyber × ai intelligence

index

tagged

[CVE-2026-59821]

1 edition · 1 item

September 11, 2026

  • Wiz scanned ~3,000 internet-facing LiteLLM gateways and found 9.6% accepted the documented example master key sk-1234 or required no auth at all — which turns a post-auth root RCE via custom code guardrails (CVE-2026-59821) into an effectively pre-auth one. An MCP endpoint auth bypass (CVE-2026-59822) lets any Bearer token mint a valid session, was confirmed exploitable on hundreds of instances, was added to CISA KEV on 2 September, and Wiz saw it exploited in the wild on its honeypots. A pass-through endpoint with no URL validation enables cloud credential theft and was not assigned a CVE or fixed. Patches exist for the rest; the work was presented at DEF CON 34 (Wiz, The Hacker News). · AI Infrastructure & Agent Security

in Four Hours to First Victim: AI Agents Ran a Global PaperCut Campaign