chiprook
← Security
SecuritySeptember 22, 2026, 03:34

CISA adds LiteLLM, Kestra and Starlette to exploited vulnerabilities list

In the second week of September 2026, CISA added seven CVEs to its Known Exploited Vulnerabilities catalog. Three target self-hosted AI infrastructure: LiteLLM (unauthenticated admin endpoint exposing all API keys), Kestra (RCE via crafted workflows) and Starlette (SSRF, the ASGI framework under FastAPI).

CISA adds LiteLLM, Kestra and Starlette to exploited vulnerabilities list
#CISA#LiteLLM#Kestra#Starlette
Read next
Security

Exim 4.100.1 fixes four flaws, including Proxy Protocol and SMTP smuggling

Security

BigCommerce alerts merchants to data breach via Ribon apps

Security

World's first naval drone clash: Ukrainian USV sinks Russian kamikaze drone boat

Security

MojeID rolls out post-quantum digital identity security