CISA added seven exploited flaws in one day, and the two with the widest blast radius are auth checks that fail open
2026-09-03Security
LiteLLM falls back to empty credentials after a failed API key check, so any bearer token opens an authenticated MCP session. Starlette lets a single malformed character in the Host header walk past path-based auth. Five of the seven additions carry a three-day deadline.