September 11, 2026
- Wiz scanned ~3,000 internet-facing LiteLLM gateways and found 9.6% accepted the documented example master key
sk-1234or required no auth at all — which turns a post-auth root RCE via custom code guardrails (CVE-2026-59821) into an effectively pre-auth one. An MCP endpoint auth bypass (CVE-2026-59822) lets any Bearer token mint a valid session, was confirmed exploitable on hundreds of instances, was added to CISA KEV on 2 September, and Wiz saw it exploited in the wild on its honeypots. A pass-through endpoint with no URL validation enables cloud credential theft and was not assigned a CVE or fixed. Patches exist for the rest; the work was presented at DEF CON 34 (Wiz, The Hacker News). · AI Infrastructure & Agent Security
in Four Hours to First Victim: AI Agents Ran a Global PaperCut Campaign