If you just remember one thing from this briefing…
Your AI gateway just became a confirmed target, not a theoretical one.
CISA's 2 September update included the first AI-infrastructure flaw it has ever listed as exploited: an
authentication bypass in LiteLLM's MCP gateway, chained with a second bug to steal provider keys and mine
cryptocurrency inside production AI proxies. Ask this week: does our AI gateway sit behind the same
network controls as every other production system, or did it go in unreviewed?
Priority2 Sep
First AI-infrastructure flaw lands in CISA's exploited-vulnerability catalogue
CISA added a LiteLLM MCP authentication-bypass flaw (CVE-2026-59822) to its exploited-vulnerabilities
catalogue on 2 September, one of seven added that day. Attackers chained it with a Starlette smuggling
bug to reach unauthenticated MCP endpoints, harvest provider keys, and deploy cryptocurrency miners
inside production gateways.
So what: any self-hosted AI gateway or MCP proxy is now a confirmed target. Patch
LiteLLM to 1.84.0 and review who has network access to it.
Priority8 Sep
Record Patch Tuesday ships two exploited Windows zero-days
Microsoft's September update fixed 974 vulnerabilities, its largest release on record, including two
zero-days already under active exploitation: a Windows Update Stack privilege-escalation flaw
(CVE-2026-81963) and an ALPC heap overflow (CVE-2026-85880), both granting SYSTEM-level access.
So what: triage the two exploited flaws ahead of the remaining 972 fixes; volume
is a scheduling problem, active exploitation is not.
Priority6-8 Sep
Maximum-severity N-central flaw hands attackers every managed endpoint at once
N-able confirmed pre-disclosure exploitation of a pre-authentication remote-code-execution flaw in
N-central (CVE-2026-86218, CVSS 10.0), its remote monitoring platform. A hotfix shipped 6 September;
CISA catalogued the flaw two days later. Chained with two auth-bypass bugs, it lets attackers create
administrator accounts outright.
So what: ask any managed service provider you use whether Hotfix 4 is applied —
one compromised console reaches every endpoint it manages.
PrioritySep
EU AI Office opens its first compliance inspection wave
Following the 2 August high-risk deadline, the AI Office and national regulators — France's CNIL,
Germany's BfDI, Spain's AESIA — began scheduled inspections this month, opening with automated
CV-screening, algorithmic credit assessment and AI triage tools in private healthcare.
So what: if you deploy AI in EU recruitment, lending or healthcare triage, assume
documentation requests are live now — check your Annex III conformity file is current.