securityonline.info 7/23/2026, 4:32:49 PM · external

Unpatched SGLang Flaw CVE-2026-14890 Allows Unauthenticated Remote Code Execution

Unpatched SGLang Flaw CVE-2026-14890 Allows Unauthenticated Remote Code Execution
CyberSIXT Evidence Panel
Primary Source kb.cert.org
CISA KEV Not in KEV
Patch Patch Status Unknown

THE content discusses a critical vulnerability identified as CVE-2026-14890 in SGLang, which allows unauthenticated remote code execution via an unprotected ZeroMQ socket. The CVSS score for this vulnerability is 9.1, indicating severe risk. Currently, no confirmed exploitations exist, but the vulnerability has no available patch, exposing users to potential attacks. Important configurations for vulnerability mitigation include disabling the expert-parallel backup subsystem and restricting service accessibility. The SGLang framework is widely used in AI applications, heightening the stakes of this security issue.

View Primary Source Via securityonline.info

Article by CyberSIXT