CuraSec

Act active

Critical Unauthenticated RCE in Bifrost AI Gateway (CVE-2026-90898)

2026-09-24 15:49 UTC · The Hacker News · read the source ↗ #rce#ai-infrastructure#open-source
  • Engineer — Act: Public PoC exists for a CVSS 9.8 unauthenticated RCE affecting all Bifrost HTTP transport versions before 2.1.0 — if you run this AI gateway in any environment, patch to 2.1.0 immediately and audit for signs of exploitation in management endpoint logs.
  • SOC/IR — Plan: No active exploitation signals yet (EPSS 0.01, not KEV-listed), but a public PoC raises near-term risk — if Bifrost appears in your estate, write a detection for unauthenticated HTTP requests to its management interface before campaigns emerge.
  • Leader — Skip
  • Signals: CVE-2026-90898 — CISA KEV: not listed, EPSS 0.01, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.