Critical Unpatched RCE Vulnerability (CVE-2026-105192) Disclosed in LMCache for LLM Servers
JFrog has disclosed a critical remote code execution (RCE) vulnerability, CVE-2026-105192, in LMCache, an open-source software used to accelerate large language model (LLM) servers. The flaw, rated 9.8 out of 10, allows unauthenticated attackers to run code on the cache server, and notably, no fixed version is currently available. This poses a significant risk to AI infrastructure utilizing LMCache in multiprocess mode with a routable address.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.
Open NewsSnap.ai