Hunter[verified]@HunterMappingDisclosure
The alert announces CVE‑2026‑59822 (an authentication bypass in LiteLLM with CVSS 8.2) and provides links to documentation and a GitHub patch, but does not mention active exploitation or exploit code.
FOFA[verified]@fofabotActive Exploitation
CVE‑2026‑59822 is an authentication bypass in LiteLLM AI Gateway, with a CVSS of 8.8, and is actively exploited in AI infrastructure attacks, as confirmed by a CISA alert and a large number of internet‑facing instances discovered via FOFA.
Slade 🛡️ LLM Hacker[verified]@llm_redteamActive Exploitation
CVE‑2026‑59822 is an authentication bypass in LiteLLM’s MCP that is actively exploited, as highlighted by CISA’s Known Exploited Vulnerabilities catalog and honeypot data, and has been patched in LiteLLM 1.84.0.
Rıdvan Yağlı[verified]@ridvanyagliActive Exploitation
CVE-2026-59822 is an authentication bypass in LiteLLM’s MCP endpoint that is actively exploited in the wild, is listed in CISA’s KEV catalog, and is fixed in version 1.84.0 and later.
Samuel McDonnell[verified]@samueljmcdActive Exploitation
The post highlights two CVEs in LiteLLM and Starlette as known exploited, explains their exploitation mechanisms, and urges immediate patching of the gateway.
Hazem Omier[verified]@hazemomierActive Exploitation
The post reports that CVE-2026-59822 (LiteLLM MCP auth bypass) is listed in CISA KEV with real-world exploitation, explains the fail-open OAuth fallback flaw, and urges immediate patching to version 1.84.0+ along with key rotation and an independent authentication layer.
H1DR4[verified]@H1DR4_agentActive Exploitation
CISA reports CVE-2026-59822 is actively exploited, affecting LiteLLM's MCP Streamable HTTP endpoint, with a federal remediation deadline of September 16, 2026; it is an authentication failure, not a prompt‑injection issue.
YourDailyCVE[verified]@YourDailyCVEPatch
CVE-2026-59822 allows an attacker to bypass LiteLLM’s API key checks by sending a fabricated Authorization header, enabling access to sensitive MCP tools. The vulnerability is mitigated by upgrading to LiteLLM 1.84.0 or disabling the MCP Streamable HTTP endpoint.