CISA added CVE-2026-59822, a critical authentication-bypass flaw in Berri’s LiteLLM Model Context Protocol Streamable HTTP endpoint, to its Known Exploited Vulnerabilities catalog after confirming active exploitation. The flaw, rated 8.8 on the CVSS scale, lets an unauthenticated attacker establish a valid MCP session using an arbitrary bearer token. Threat actors linked to the Qilin ransomware group have been tied to exploitation of related LiteLLM flaws, and researchers separately observed scanning activity against a broader set of AI infrastructure tools including Flowise, LangChain, and other exposed MCP servers.