Cve 2026 42271 · AI Security

Google GTIG Counts 141 Exploited Flaws in 8 Months; Patch LiteLLM and Langflow First

Data graphic: A giant red "141" marks the exploited vulnerabilities Google's threat intelligence group recorded from January to August 2026, against 127 for all of 2025. Below it are the fixed versions for the two exploited AI-stack flaws, LiteLLM 1.83.7 CVE-2026-42271 and Langflow 1.9.0 CVE-2026-5027 .
OP

AI security researcher · Updated Oct 3, 2026, 5:45 AM EDT

Google's GTIG logged 141 exploited flaws in Jan–Aug 2026, more than all of 2025, and lists LiteLLM CVE-2026-42271 and Langflow CVE-2026-5027 as exploited.

Google Threat Intelligence Group (GTIG) says it saw more vulnerabilities exploited in the first eight months of 2026 than in the whole of 2025: 141 against 127. Its new report names three AI-stack flaws as exploited in the wild. Two are recent: LiteLLM CVE-2026-42271 and Langflow CVE-2026-5027. GTIG also says it has not yet seen zero-day exploitation of AI infrastructure. The risk is patch lag on exposed AI middleware, so teams running LiteLLM or Langflow should confirm they are on the fixed versions below.

What happened

On 1 October 2026 GTIG published Vulnerability discovery and exploitation trends in the AI era. The headline figures, all from the report:

  • 141 exploited in eight months. "From January 2026 to August 2026, GTIG recorded 141 distinct vulnerabilities disclosed and exploited, surpassing the total number of vulnerabilities exploited for the full year of 2025 (127)." That is an average of 18 a month, up from 10.5 a month in 2025.
  • Zero-days overall rose slightly. Across all software, zero-day exploitation went from an average of 8 a month in 2025 to 11 a month in 2026.
  • Disclosures doubled. Monthly CVE disclosures went from 5,045 in January 2026 to 10,740 in August. GTIG notes that only 0.23% of 2026 disclosures, roughly 1 in 431, were seen exploited.
  • AI CVEs are piling up. GTIG counted 2,076 AI-related CVEs from January 2025 to August 2026, "with over 1,500 vulnerabilities identified from January 2026 to August 2026 alone."

On AI infrastructure specifically, GTIG writes: "While zero-day exploitation of AI infrastructure has not yet been observed, threat actors are actively weaponizing newly disclosed vulnerabilities in exposed middleware." Out of the 2,076 AI disclosures, it says "only a handful" have been confirmed as exploited. It lists three, all rated High Threat Risk:

CVEProductWhat GTIG says it allowsFixed inCISA KEV
CVE-2026-42271BerriAI LiteLLMCommand injection in the MCP server preview endpoint, leading to host takeover and API credential theft1.83.7Yes, added 8 June 2026
CVE-2026-5027LangflowPath-traversal file write in the upload handler, used to drop files such as cron jobs or SSH keys1.9.0No
CVE-2025-3248LangflowUnauthenticated Python code injection via exec() in /api/v1/validate/code1.3.0Yes, added 5 May 2025

Why it matters

GTIG's breakdown shows where AI CVEs are landing. The 2026 counts by stack layer, with some of the products GTIG lists for each:

Data graphic: lollipop chart of GTIG's AI-related CVE counts by stack layer, Jan–Aug 2026, on a linear scale from zero. Orchestration and agent frameworks lead with 782, ahead of AI web apps and portals 230 and inference and serving 212 . The orchestration layer Langflow CVE-2026-5027 and the inference and serving layer LiteLLM CVE-2026-42271 are marked orange as exploited.

AI-related CVEs by stack layer, Jan–Aug 2026 (GTIG). The highlighted layers hold the exploited Langflow and LiteLLM flaws.

Layer (GTIG)Example products named by GTIG2026 CVEs
AI orchestration and agent frameworksFlowise, Langflow, LangChain, Dify, LlamaIndex, MCP782
AI web apps and portalsOpen-WebUI, AnythingLLM, LibreChat, RAGFlow, Gradio230
Inference and servingvLLM, Ollama, LiteLLM, Llama.cpp, Triton, Ray212
Model security advisoriesModel weights, system prompts, guardrails106
ML frameworks and hubsPyTorch, Hugging Face Transformers, ONNX Runtime99
Frontier modelsAnthropic, Gemini, OpenAI97
MLOps and experiment trackingMLflow, ClearML, Weights & Biases, Kubeflow39
Vector databases and searchMilvus, Qdrant, ChromaDB, Weaviate19

The two recent exploited flaws sit in the two layers that are most often deployed as network services: an AI gateway (LiteLLM, inference and serving) and a visual workflow builder (Langflow, orchestration). Both products usually hold upstream model-provider API keys, so code execution on either host is also a credential-theft problem.

How fast the exploitation follows disclosure matters for patch windows too. GTIG's timing example is outside AI: BeyondTrust CVE-2026-1731 was exploited by one threat cluster "within four days of public disclosure," and by five more within seven days.

Technical details

LiteLLM CVE-2026-42271. Per the GitHub advisory, two endpoints that test an MCP server before it is saved, POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list, accept a full stdio server configuration (command, args, env). The proxy starts that command as a subprocess with its own privileges. The endpoints were gated only by a valid proxy API key, with no role check, so a low-privilege internal-user key was enough.

  • Affected: litellm 1.74.2 up to, but not including, 1.83.7.
  • Fixed: 1.83.7, where both endpoints require the PROXY_ADMIN role.
  • Score: NVD rates it CVSS 3.1 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). GitHub, as CNA, gives CVSS 4.0 8.7. CWE-77 and CWE-78.
  • CISA added it to KEV on 8 June 2026. NVD also lists affected Red Hat OpenShift AI builds (2.25 before 2.25.8, 3.3 before 3.3.4, and 3.4).

We covered how this flaw was chained with a Starlette bug in AI Gateway Compromise: Chained Starlette and LiteLLM Flaws Expose Foundation Model Keys.

Langflow CVE-2026-5027. The POST /api/v2/files upload handler does not sanitize the filename field of the multipart request, so ../ sequences write a file anywhere the Langflow process can write. GTIG says attackers use it to drop cron jobs or SSH keys, which turns the file write into code execution or persistent access.

  • Affected: versions before 1.9.0 (NVD).
  • Fixed: 1.9.0. Tenable's advisory says the vendor confirmed the fix on 11 June 2026, about 11 weeks after the CVE was published on 27 March.
  • Score: CVSS 3.1 8.8, same vector as above, assigned by Tenable as CNA. NVD has not added its own score. CWE-22.
  • Requires authentication (PR:L). Credited to Joshua Martinelle (Tenable TRA-2026-26).

GTIG's summary sentence groups the three flaws as providing "unauthenticated RCE, command injection, or arbitrary file writes". The vendor and CNA records say both CVE-2026-42271 and CVE-2026-5027 need a valid credential. For LiteLLM that bar is low: the advisory says a low-privilege internal-user key was enough. Whether attackers in the cases GTIG saw had stolen credentials or used open registration, the report does not say.

What defenders should do

A patch order based on GTIG's findings: exploited flaws first, then internet-exposed AI middleware, then the rest of the stack.

  1. Patch the exploited flaws.
    • LiteLLM: upgrade to 1.83.7 or later. If you cannot yet, block POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list at the reverse proxy, which is the workaround the advisory gives. On OpenShift AI, apply Red Hat's fixed builds.
    • Langflow: upgrade to 1.9.0 or later. That also covers the older CVE-2025-3248, which NVD lists as fixed in 1.3.0. If you missed CVE-2026-33017, see our Langflow CVE-2026-33017 coverage.
  2. Check for compromise on hosts that ran vulnerable versions. Patching does not undo a compromise. On LiteLLM, search proxy logs for requests to the two /mcp-rest/test/ endpoints from non-admin keys, and rotate the master key and every provider API key the gateway stored. On Langflow, look for unexpected files in cron directories and authorized_keys, and for uploads whose filenames contain ../.
  3. Next, internet-exposed AI middleware. That means gateways, workflow builders and MCP endpoints. Two of GTIG's layers hold most of these: orchestration (782, the largest layer) and inference and serving (212, third): Flowise, Dify, Langflow, LiteLLM, Ollama, vLLM and Ray. Take admin and builder interfaces off the public internet, put them behind SSO or a VPN, and cut down who holds API keys. Earlier LiteLLM flaws are another reason to keep it current: see LiteLLM CVE-2026-42208.
  4. Treat any endpoint that accepts an MCP server command as code execution by design. Limit it to administrators, wherever it lives.
  5. Then the rest: AI web apps and portals (230, the second-largest layer, ranked here on exposure rather than size), then ML frameworks, MLOps and vector databases. GTIG lists no exploited flaw in these layers, but check whether any of these services, chat front ends especially, can be reached from the internet.
  6. Shorten the window. GTIG's own advice is to move "from unprioritized mass-patching to threat-intelligence-driven triage" and to sandbox agentic workloads. For AI middleware, that means treating a new KEV entry or vendor exploitation report as a patch-in-days item.

What is still unclear

  • GTIG does not say who exploited either flaw, when exploitation began, or how many systems were hit.
  • CVE-2026-5027 is not in CISA's KEV catalog as of the 2 October feed. When the CVE was published in March, CISA's SSVC assessment in NVD recorded exploitation as "none". GTIG's report is the only public source we found that confirms it was exploited.
  • GTIG's report and the vendor records disagree on whether the two recent flaws need authentication (see above). We follow the advisories.
  • We found no Langflow release note for the 1.9.0 fix. The fixed version comes from NVD and Tenable.
  • GitHub's advisory database dates the LiteLLM advisory 25 April 2026; NVD published the CVE on 8 May.

This article will be updated if GTIG, CISA or the vendors publish more detail.

Sources