The AI Gateway Becomes a Target: Measuring LiteLLM and Kestra Exposure
On September 2, 2026, CISA added vulnerabilities in AI gateway LiteLLM (CVE-2026-59822, CVSS 8.8) and orchestration platform Kestra (CVE-2026-49869, CVSS 10.0) to the Known Exploited Vulnerabilities catalog. 34,412 LiteLLM and 126 Kestra installations are exposed online, risking theft of API keys to LLMs.
- LiteLLM: CVE-2026-59822, CVSS 8.8, 34,412 exposed installations
- Kestra: CVE-2026-49869, CVSS 10.0, 126 exposed installations
- Langflow — 18,448 matches, Metabase — 115,725
- Risk: leakage of API keys to models and work tokens
Read next
Security