Act
active
Critical Unauthenticated RCE in Bifrost AI Gateway (CVE-2026-90898)
- Engineer — Act: Public PoC exists for a CVSS 9.8 unauthenticated RCE affecting all Bifrost HTTP transport versions before 2.1.0 — if you run this AI gateway in any environment, patch to 2.1.0 immediately and audit for signs of exploitation in management endpoint logs.
- SOC/IR — Plan: No active exploitation signals yet (EPSS 0.01, not KEV-listed), but a public PoC raises near-term risk — if Bifrost appears in your estate, write a detection for unauthenticated HTTP requests to its management interface before campaigns emerge.
- Leader — Skip
- Signals: CVE-2026-90898 — CISA KEV: not listed, EPSS 0.01, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.