Skip to content
Critical CVEs Affecting AI Inference Services: CVE-2026-93688 and CVE-2026-92983

Critical CVEs Affecting AI Inference Services: CVE-2026-93688 and CVE-2026-92983

First seen 19 Sep 2026, 01:56 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 19, 2026 at 01:58 UTC
  • CVE-2026-93688 and CVE-2026-92983 allow unauthenticated memory exhaustion attacks.
  • Both vulnerabilities pose high availability risks for AI inference services.
  • Immediate patching and monitoring are crucial for affected organizations.

Two high-priority vulnerabilities have been identified in AI inference services: CVE-2026-93688 in SGLang and CVE-2026-92983 in InternLM. Both vulnerabilities allow unauthenticated attackers to exploit exposed endpoints, leading to denial of service through memory exhaustion. CVE-2026-93688 affects SGLang versions up to 0.5.19, while CVE-2026-92983 impacts InternLM LMDeploy versions up to 0.17.0. Attackers can submit arbitrary requests to exhaust memory, disrupting model serving and dependent applications. The vulnerabilities are not currently classified as actively exploited, but organizations using these systems should take immediate action to mitigate risks. Monitoring for unusual request patterns and applying vendor patches are recommended. The vulnerabilities were published on September 18 and September 17, 2026, respectively.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-09-17
CVE-2026-92983 published
InternLM LMDeploy vulnerability disclosed, allowing memory exhaustion via unauthenticated requests.
Redpacketsecurity
2026-09-18
CVE-2026-93688 published
SGLang vulnerability disclosed, enabling denial of service through memory allocation exhaustion.
Redpacketsecurity
2026-09-19
Current status assessment
Both vulnerabilities assessed as high risk but not actively exploited; organizations urged to patch.
Redpacketsecurity

More articles in this cluster (2)

Following this threat?

Track CVE-2026-92983 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed