LMCache ships a critical, unpatched RCE reachable with a single ZeroMQ message on vLLM servers
On October 7, 2026, JFrog disclosed CVE-2026-105192, an unauthenticated remote code execution flaw rated 9.8 in LMCache, the cache layer that speeds up LLM servers such as vLLM, with no fix available. If your LMCache cache listens on a routable address, isolate it now instead of waiting for a patch.