CISA adds LiteLLM, Kestra and Starlette to exploited vulnerabilities list
In the second week of September 2026, CISA added seven CVEs to its Known Exploited Vulnerabilities catalog. Three target self-hosted AI infrastructure: LiteLLM (unauthenticated admin endpoint exposing all API keys), Kestra (RCE via crafted workflows) and Starlette (SSRF, the ASGI framework under FastAPI).
- LiteLLM: unauthenticated admin endpoint exposes every routed API key
- Kestra: RCE through crafted workflow definitions
- Starlette: SSRF flaw in the ASGI framework under FastAPI
- Full attack chain from Shodan scan to cryptominer takes under an hour
Read next
Security