Vulnerabilities & Exploits

Microsoft Broadens AI Gateway Abuse to Three Workloads

On day 15, Microsoft said the LiteLLM activity has widened into a broader pattern across three AI workloads: LiteLLM, RAGFlow, and Kestra. The company said attackers are treating exposed AI gateways and workflow layers as control points for credential theft, persistence, and cryptomining, not just one-off product bugs.

The issue is the trust these services hold. Microsoft said they can sit on model-provider keys, virtual keys, database connection strings, tenant policy, and execution rights, so a foothold in the middle tier can be reused to reach the systems behind it; in LiteLLM’s case, the observed path includes CVE-2026-42271.

For teams running AI gateways, orchestration, or agent tooling, the exposure lives in the management layer and whatever it can already access. Patching the visible flaw does not erase secrets or downstream paths if the service was already acting as the bridge between users, models, and internal systems.

26 sources · Aug 28

CVE-2026-42271

NVD KEV

Known exploited · CISA KEV

CVSS 8.8 HIGH: liteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. EPSS 84% (100th percentile).

CISA federal remediation date Jun 22 · date passed

Timeline

Sources

Part of the PlainSec briefing for 2026-08-20

Every edition of this story: Microsoft Broadens AI Gateway Abuse to Three Workloads

More from today