Last updated: October 8, 2026 at 8:36 AM UTC
All 909 Vulnerability 368 Breach 144 Threat 390 Defense 7
Tag: llm-infrastructure (2 articles)Clear

Unpatched critical LMCache flaw lets unauthenticated attackers run code on exposed LLM cache servers

JFrog disclosed CVE-2026-105192, a critical flaw rated 9.8 in LMCache, open-source software that speeds up LLM servers such as vLLM. In multiprocess mode the cache runs as a standalone server reached over ZeroMQ with no authentication, and one message type is deserialized with pickle before its type is checked, letting a crafted message run code. The server is exposed only when an operator binds it to a routable address rather than the default localhost, and the code runs with LMCache's privileges, which are root in the project's official container images. No fix exists yet, and JFrog advises keeping the port on localhost or a trusted cluster network.

Check
Inventory LMCache deployments, confirm the ZeroMQ cache server is bound only to localhost or a trusted cluster network, and avoid exposing it on routable addresses until a fix ships.
Affected
LMCache 0.3.9 through 0.5.5 in multiprocess mode exposes an unauthenticated ZeroMQ socket that deserializes pickle data, letting a remote attacker run code as root on bound servers.
Fix
Keep the LMCache port on localhost or a trusted network, restrict network access to LLM cache hosts, and watch for an upstream patch since none is available yet.

PoeLLM cryptomining malware infects 3,400 exposed AI and web servers through known vulnerabilities

Lumen Black Lotus Labs detailed PoeLLM, the malware behind the financially motivated Canto Incognito campaign, which has infected more than 3,400 internet-facing servers since April 2026. The actor hides its command-and-control address inside a poem stored in a GitHub repository, changing a few words whenever it rotates infrastructure. It exploits known vulnerabilities in exposed services such as LiteLLM, Gotenberg, Gitea, and Ivanti Sentry, then installs XMRig and Iron miners to abuse victim compute for cryptocurrency mining through a Russian mining service. Compromised hosts become scanners and exploit servers that spread the malware further, and recent traffic suggests experimentation with distributed brute-force attacks.

Check
Patch known vulnerabilities in internet-facing LiteLLM, Gotenberg, Gitea, and Ivanti Sentry deployments, and inspect servers for XMRig or Iron miner processes and unexpected outbound scanning.
Affected
Exposed servers running vulnerable LiteLLM, Gotenberg, Gitea, or Ivanti Sentry can be infected by PoeLLM, turned into cryptominers, and reused to scan and infect further hosts.
Fix
Apply available patches to exposed services, remove miner payloads and attacker accounts, restrict inbound access to management and AI services, and monitor for outbound exploit scanning.