chiprook
← Security
SecurityOctober 7, 2026, 22:34

Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely

A critical vulnerability in LMCache, open-source software that accelerates large language model servers such as vLLM, allows an attacker to run code on the cache server without logging in. The flaw affects LMCache's multiprocess mode, where the cache runs as a standalone server reached over ZeroMQ, and no fixed version is available.

Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely
#LMCache#VLLM#ZeroMQ
Read next
Security

CVE-2026-12227: Critical unauthenticated LFI in Visual Composer WordPress plugin

Security

Critical Bifrost AI Gateway Flaw Allows Unauthenticated Command Execution

Security

Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files

Security

OnePlus leaves OxygenOS root flaws unpatched for six months