⌁AI·CYBER·BRIEF▌

#Moonshot AI

Vulnerabilities8 min read

Mooncake, the KV cache layer under vLLM and SGLang, has two unauthenticated flaws — one unfixed

Two CVEs published October 1, 2026 in Mooncake's transfer engine. One lets anyone on the network read and write process memory; the other has no released fix.

CVE-2026-103764CVE-2026-103765Mooncake