Executive Summary
A critical vulnerability (CVE-2026-105192) in LMCache, an open-source caching system for large language model servers, allows unauthenticated remote code execution with a severity score of 9.8/10. The flaw affects LMCache versions 0.3.9 through 0.5.5 in multiprocess mode, where attackers can exploit Python pickle deserialization through ZeroMQ messaging to execute arbitrary code. The vulnerability particularly impacts deployments using routable network addresses, including LMCache's own Kubernetes example configuration, with no patch currently available.
This incident highlights the growing security risks in AI infrastructure as organizations rapidly adopt LLM technologies without adequate security controls. The vulnerability represents a broader trend of supply chain risks in AI frameworks, following similar ShadowMQ vulnerabilities discovered across multiple AI inference platforms in 2025.
Why This Matters Now
AI infrastructure is experiencing explosive growth with inadequate security practices, making critical vulnerabilities like CVE-2026-105192 particularly dangerous as organizations deploy LLM systems without proper security hardening or network isolation.
Attack Path Analysis
Attackers exploited CVE-2026-105192 in LMCache's multiprocess mode to achieve remote code execution via unauthenticated pickle deserialization on ZeroMQ transport. The vulnerability allowed immediate root-level access on container deployments, enabling lateral movement across trusted cluster networks, establishing command channels through compromised cache infrastructure, exfiltrating cached AI model data and tenant information, and potentially disrupting LLM inference services across the supply chain.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers targeted publicly exposed LMCache multiprocess servers listening on routable addresses, exploiting CVE-2026-105192 to send crafted pickle-serialized messages via unauthenticated ZeroMQ sockets for remote code execution
Related CVEs
CVE-2026-105192
CVSS 9.8A critical vulnerability in LMCache's multiprocess mode allows unauthenticated remote code execution via pickle deserialization on the ZeroMQ transport when the server is configured with a routable address.
Affected Products:
LMCache LMCache – 0.3.9, 0.4.0, 0.4.1, 0.4.2, 0.5.0, 0.5.1, 0.5.2, 0.5.3, 0.5.4, 0.5.5, 0.5.6-rc
Exploit Status:
proof of conceptReferences:
https://research.jfrog.com/vulnerabilities/lmcache-is-vulnerable-to-unauthenticated-remote-code-execution-via-pickle-deserialization-on-the-multiprocess-zmq-transport-cve-2026-105192-jfsa-2026-001694382/https://www.cve.org/CVERecord?id=CVE-2026-105192https://github.com/LMCache/LMCache/blob/v0.5.5/lmcache/v1/platform/base/ipc_wrapper.pyCVE-2026-105756
CVSS 6.5A denial-of-service vulnerability in vLLM before version 0.30.0 allows a single request with malformed cache_salt value to crash the engine on deployments using LMCache multiprocess connector.
Affected Products:
vLLM vLLM – < 0.30.0
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Exploitation for Client Execution
Process Injection
Exploitation for Privilege Escalation
Impair Defenses: Disable or Modify Tools
Network Denial of Service
Data Manipulation: Stored Data Manipulation
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Custom Software Development Processes
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Risk Assessment
Control ID: 500.09
DORA – ICT Risk Management Framework
Control ID: Article 8
CISA ZTMM 2.0 – Micro-segmentation and Access Controls
Control ID: Network Segmentation
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO 27001 – Management of Technical Vulnerabilities
Control ID: A.12.6.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Critical supply-chain vulnerability in LMCache affects AI infrastructure, enabling unauthenticated remote code execution through pickle deserialization in multiprocess deployments.
Information Technology/IT
Unpatched LMCache flaw exposes IT service providers using LLM servers to remote code execution, compromising client data and violating compliance frameworks.
Health Care / Life Sciences
Healthcare AI systems using vulnerable LMCache face HIPAA violations through potential data exfiltration and unauthorized access to protected health information.
Financial Services
Banking institutions deploying AI models with LMCache risk regulatory non-compliance and data breaches through exploitable ZeroMQ authentication bypass vulnerabilities.
Sources
- Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotelyhttps://thehackernews.com/2026/10/unpatched-critical-lmcache-flaw-lets.htmlVerified
- JFrog Security Research - LMCache Vulnerable to Unauthenticated Remote Code Executionhttps://research.jfrog.com/vulnerabilities/lmcache-is-vulnerable-to-unauthenticated-remote-code-execution-via-pickle-deserialization-on-the-multiprocess-zmq-transport-cve-2026-105192-jfsa-2026-001694382/Verified
- CVE-2026-105192 Recordhttps://www.cve.org/CVERecord?id=CVE-2026-105192Verified
- vLLM Security Advisory GHSA-2823-qmq8-rwvjhttps://github.com/vllm-project/vllm/security/advisories/GHSA-2823-qmq8-rwvjVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce the blast radius of this LMCache supply chain attack by constraining lateral movement across cluster networks and limiting unauthorized access to cached AI model data through workload segmentation.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Zero Trust fabric policies would likely constrain initial attack surface by reducing the reachability of LMCache services from untrusted network zones and limiting external exposure of multiprocess endpoints
Control: Zero Trust Segmentation
Mitigation: Zero Trust segmentation would likely limit the scope of compromised LMCache container privileges by constraining access to host resources and reducing the blast radius of root-level container access through workload isolation
Control: East-West Traffic Security
Mitigation: East-west traffic enforcement would likely constrain lateral movement by reducing attacker reachability across cluster networks and limiting access between compromised cache infrastructure and connected vLLM workers through microsegmentation policies
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility and control would likely limit command channel establishment by constraining unauthorized outbound communications from compromised cache infrastructure and reducing attacker persistence across distributed cluster environments
Control: Egress Security & Policy Enforcement
Mitigation: Egress policy enforcement would likely constrain data exfiltration by limiting unauthorized outbound data flows from compromised cache servers and reducing the scope of accessible cached AI model data through controlled egress paths
While some AI inference service disruption may still occur, the overall supply chain impact would likely be reduced in scope due to constrained lateral reach and limited access to downstream LLM workloads through segmented infrastructure boundaries
Impact at a Glance
Affected Business Functions
- AI/ML Model Inference
- Large Language Model Services
- Distributed Computing Infrastructure
- Cloud-based AI Applications
Estimated downtime: N/A
Estimated loss: N/A
Potential unauthorized access to cached LLM data across different tenants, possible exposure of model inference results, and risk of code execution with root privileges on affected container deployments. No confirmed data breach reported but architectural vulnerability allows cross-tenant data access.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust segmentation with identity-based policies to prevent lateral movement from compromised cache infrastructure to critical AI workloads and Kubernetes clusters
- • Deploy inline IPS with signature-based detection to identify and block known exploit patterns targeting CVE-2026-105192 and similar pickle deserialization vulnerabilities
- • Enforce egress security policies to detect and prevent unauthorized data exfiltration from AI cache servers and limit outbound connections to approved destinations only
- • Enable multicloud visibility and anomaly detection to identify suspicious automation patterns, repeated malformed requests, and unauthorized access to multi-tenant cached data
- • Establish Kubernetes security controls with namespace enforcement and pod-to-pod segmentation to contain supply chain compromises affecting containerized AI inference infrastructure



