On 2 September CISA added seven CVEs to KEV. For people running AI infrastructure, two stand out: LiteLLM lets anyone with a made-up token reach the MCP tools, and Artifactory hands out admin rights without a login. The deadline for Artifactory and SonicWall is 5 September.
- CVE-2026-59822 in LiteLLM: the MCP endpoint can accept an arbitrary Bearer token; fixed in 1.84.0, and meanwhile /mcp/ can be blocked.
- CVE-2026-82329 in JFrog Artifactory: under default configuration an attacker without a login becomes admin; cloud is protected, self-hosted servers must update.
- Also: SonicWall SMA1000 (CVE-2026-83548 with CVSS 10.0 and CVE-2026-83549), Starlette, Kestra and Sangoma Switchvox.
A made-up token. Literally any string after the word Bearer, and a vulnerable LiteLLM can let you through to the tools you have wired to your agents.
LiteLLM is the gateway teams use to route requests to different models. If MCP tools hang off it - a database, email, an internal API - an attacker can list them and call them.
Artifactory, again, and again without confusing things
The name enters KEV for the second time in a week. On 27 August it was a milder flaw that needs a login. This one is from the other end: no login, default configuration, straight to admin. JFrog published it on 28 August, and CISA gives three days.
Artifactory was also the stage of the incident OpenAI described on 26 August. Neither JFrog nor CISA links this CVE to it, and we will not either. What they share is something else: the internal package server turned out to be a far more interesting target than the network diagrams say.
If your network has LiteLLM with MCP tools attached, update to 1.84.0 or close /mcp/ tonight. Self-hosted Artifactory gets updated to the version for your branch. For SonicWall SMA1000: the latest hotfix and a conversation with their support about traces of compromise, because that is what their advisory says.