MikeTrendsTrends right now

search

CVE-2026-103041

Trends

  1. 1
    Three unpatched critical flaws disclosed in LightLLM▼🚨 LightLLM Mass Disclosure — 3 CVEs, no patch CVE-2026-103040 (CVSS 9.8) — unauthenticated RCE, router profiler RPyC CVEMmastodonTechnologyAI41 h ago

    Three vulnerabilities in LightLLM, an open-source large language model serving framework, have been disclosed without an available patch. The most serious, CVE-2026-103040, is rated 9.8 and allows unauthenticated remote code execution via the router profiler RPyC interface. A similar flaw, CVE-2026-103041, also rated 9.8, affects the embed cache RPyC service, while CVE-2026-103042, rated 7.5, enables memory exhaustion through the NCCL control channel. Security researchers are urging exposed deployments to restrict network access.

  2. 2
    Critical LightLLM flaw exposes AI servers to remote code execution●🚨 CVE-2026-103041 — CVSS 9.3 CRITICAL LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cacheMmastodonTechnologyCybersecurity05 h ago

    A critical vulnerability, CVE-2026-103041, has been disclosed affecting LightLLM through version 1.2.0. In multimodal deployments, the software exposes an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. Security researchers warn attackers can send crafted serialized objects to exposed cache methods to execute arbitrary code remotely. With a CVSS score of 9.3, admins running LightLLM are being urged to review exposed services and update as soon as possible.