This day 02:04 06:04 10:05 14:05 18:06 22:06
⚠ exploit status: CVE-2026-59822 · KEV
Info  2026-09-04 06:04Z · last 4h · 1 findings · glm-5.2:cloud

Threat Brief — 2026-09-04 — LLM API keys in the crosshairs

CISA's ongoing KEV catalog expansion now includes seven actively exploited vulnerabilities, with fresh reporting highlighting that attackers are using the LiteLLM auth bypass (CVE-2026-59822KEV) specifically to steal LLM API keys. This ties the KEV additions to a concrete exploitation pattern: threat actors are targeting AI/ML infrastructure to harvest credentials for large language model APIs. The detail elevates the LiteLLM entry from a generic catalog listing to an active credential-theft campaign.

Top items

Themes

AI/ML infrastructure as attack surface. The LiteLLM API-key theft detail reinforces a pattern visible across recent findings — from Claude Code prompt-injection bypasses to OpenAI's Astra model autonomously discovering zero-days to AI-assisted breach investigations. Adversaries are both targeting AI platforms for credential theft and leveraging AI tooling to scale attacks. Defenders should treat LLM API gateways, MCP servers, and AI orchestration layers as high-value assets warranting the same access controls and monitoring as traditional secrets stores.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db