What happened
- On September 11, CERT/CC published CVE-2026-86793, which affects SGLang, an open-source framework for serving language models on your own infrastructure.
- According to the official record, the framework allows unauthenticated deserialization of data through the
/update_weights_from_tensorendpoint when no access keys are configured. The flaw is classified as CWE-94, code injection, and affects all versions up to 0.5.18. - It was reported by Reuel Magistrado, a researcher at VicOne. The technical analysis describes how the SafeUnpickler protection is bypassed because its list of allowed modules admits the entire
builtinsmodule, while its blocklist covers some dangerous functions but leaves out others that lead to the same result. - The report was communicated to the project on July 2 and to CERT/CC on July 16. The identifier was reserved on September 8 and published on the 11th, with no patch available.
- It’s the fourth critical flaw disclosed in AI infrastructure in 18 days, after cases in Ollama’s deployment wrapper, DeepSeek’s agent runtime and IBM Langflow.
Why it matters
- The four flaws share a cause, and it isn’t technical: they’re control APIs exposed without authentication because the software prioritizes ease of installation. In three of the four cases the problem appears with the default configuration.
- Many of the companies in Chile that say “we run our own model” do so with a framework of this kind on a virtual machine and with no API key configured, because it was never needed for it to work. The condition that triggers this flaw is exactly that.
- For anyone selling or buying private AI on the argument that the cloud is the risk: the attack surface moves; it doesn’t disappear. On your own infrastructure, the blast radius includes every model that server hosts and every application that depends on it, and credential theft still happens on the user’s computer, where the password protects nothing.
The number
18 days. The window between August 25 and September 11 in which the four critical flaws were disclosed.
Context
The pace of disclosures in this kind of component went from roughly one a month during 2025 to about one a week in the third quarter of 2026, according to the count published by Forkast. It’s not just greater scrutiny: it’s quickly integrated software entering production before compensating controls exist.
What’s next
- The project hadn’t published a patch or a public response at the time of disclosure.
- The standard recommendation for unpatched cases is to restrict network access to the service and configure authentication, something the CVE record itself notes as a condition for the flaw to be exploitable.
- No timelines announced by the maintainers.
Bottom line
On the same September 11, GreyNoise researchers documented a campaign in which hundreds of automated agents exploited two PaperCut vulnerabilities and compromised 395 organizations in 48 countries. The two stories arrived on the same day and point to the same place: the fragile link in AI in production isn’t the model; it’s the software around it. There’s already an open debate about where the real risk lives.


