Back to all news
Security

Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely

The Hacker News·October 7, 2026·1 min read
Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely

A critical unpatched vulnerability in LMCache, open-source software that accelerates LLM servers like vLLM, allows unauthenticated attackers to execute code remotely. The flaw exists in LMCache's multiprocess mode, where the cache runs as a standalone server communicating via ZeroMQ. No fixed version is available, leaving systems exposed to potential remote code execution attacks.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store