Feeds.Feedburner Critical LMCache Flaw Enables Unauthenticated Remote Code Execution
Article Content
- •CVE-2026-105192 allows unauthenticated remote code execution in LMCache.
- •The vulnerability affects versions 0.3.9 to 0.5.5, with a CVSS score of 9.8.
- •No patch is available; operators are advised to limit server exposure.
A critical vulnerability (CVE-2026-105192) in LMCache, an open-source caching software for large language models, allows unauthenticated attackers to execute code remotely. The flaw exists in the multiprocess mode, where a ZeroMQ socket is exposed without authentication, enabling exploitation via crafted messages. The vulnerability affects versions 0.3.9 through 0.5.5, with no patch available as of October 7, 2026. JFrog, which disclosed the flaw, assigned it a CVSS score of 9.8, indicating critical severity. Attackers can exploit the flaw if the server is configured to listen on a routable address. The default configuration is safer as it binds to localhost. JFrog advises operators to avoid exposing the multiprocess server to untrusted networks until a fix is released. No has been reported in the wild.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track JFrog and CVE-2026-105192 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What versions of LMCache are affected?
Is there a patch available for this vulnerability?
What should operators do to mitigate the risk?
Continue Reading
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…