Security1 distinct publisher2 min readPublished
Censys counts more than 294,000 public IPs running one of 43 AI or LLM tools, up from roughly 183,000 in October 2025. The two platforms it names for growth, Langflow and LiteLLM, both carry KEV-listed flaws.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Langflow is the cleaner attacker story. Censys flags multiple unauthenticated remote code execution flaws as raising compromise risk on internet-exposed instances [5], which means no credential step and no user interaction against a host whose function is to execute workflow code. The LiteLLM route runs through the database instead: Censys describes CVE-2026-42208 as an actively exploited pre-authentication SQL injection now carried in CISA's KEV catalog [7]. Both classes sit before authentication, which is what makes a raw exposure count operationally meaningful rather than academic.
The scale reads better as a subtraction. 294,000 minus 183,000 is about 111,000 public IPs that became visible in nine months [13], roughly 12,300 a month [14]. Censys observed about 138,000 internet-exposed ICS hosts in early 2026 [9]. So the nine-month AI addition alone is close to 80% of the entire global exposed ICS estate [16], and the AI total is about 2.1 times that estate [15]. The ICS number moved about 7% across two years by comparison [18].
Severity distribution is the second tell. Of the 18 Langflow CVEs Censys counts between 2024 and 2026, 14 score above CVSS 8.0 [4], or 78% of the total [19]. Four of them reached KEV [4], which is the subset with confirmed exploitation attached.
The ICS series is the useful control here, because it shows what these populations do once counted. Censys reports that about 70% of exposed ICS hosts have appeared on consumer and mobile networks rather than enterprise ones for two and a half years running [10]; applied to the 138,000 total, that is roughly 96,600 systems outside managed environments [20]. The map moved over the same period, with North America at about 38% of exposures, Asia rising from 22.9% in 2024 to 27% in 2026, and Europe falling from 36.1% to 31.1% [11]. The hosting environment did not move at all. That is the prior to carry into the AI figures: populations like this get measured for years before anyone switches them off, and the 294,000 hosts running AI tooling are appearing on the internet faster than the ICS estate anyone has been arguing about since 2024 [2][9].
Ranked by verification strength, evidence, and original report placement.
Early findings from the 2026 Censys State of the Internet Report show internet-exposed AI/LLM tools rose more than 60% over the past nine months.
Censys identified more than 294,000 distinct public IP addresses exposing one of 43 AI and LLM tools, compared with approximately 183,000 in October 2025.
Langflow, an open-source framework for building AI workflows, grew 169% during the reporting period; LiteLLM grew 97% over the same period.
Between 2024 and 2026 Langflow accumulated 18 CVEs, including 14 with CVSS scores above 8.0 and four entries in CISA's KEV catalog.
Censys says multiple unauthenticated remote code execution vulnerabilities increase the risk of compromise for internet-exposed Langflow instances.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 28, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
Attackers hid a cryptominer inside a LiteLLM MCP config test that reported success1 distinct publisher
security
Someone enumerated LiteLLM's key tables 36 hours after the advisory hit defender feeds1 distinct publisher
science
OX Security says MCP command execution is a design choice, so server owners own the risk1 distinct publisher
build
Ornith-1.0's benchmarks are fine. Ollama can't parse its tool calls.1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One vendor preview, restated once
Every figure here — the 294,000 addresses, the 60% rise, the 169% and 97% growth rates, the ICS averages — comes from Censys describing research it has not yet published, and reaches us through a single trade write-up. The parts that can be checked outside Censys are the strongest: CVE-2026-42208 and Langflow's KEV entries live in a public catalog. The parts that carry the story's weight cannot be checked at all, because no fingerprint list, scan cadence, or margin of error is disclosed.
Scan-measured footprint, unversioned
Unusually for an AI story, the adoption number is not a vendor's customer count — it is a census of things answering on the public internet, and 294,000 addresses across 43 tools with a named October 2025 baseline is real measurement. Two named projects have growth rates attached and both appear in an exploitation catalog, which is about as concrete as deployment evidence gets. What holds the score down is that reachable is not the same as running-in-production, and nobody has told us how the 43 tools are fingerprinted.
Direction solid, threat math thin
The overstatement is structural rather than rhetorical. eSecurity Planet's language is restrained, but pairing a total exposure count with a severe CVE record invites the reader to treat 294,000 hosts as 294,000 targets, and no line in the reporting supports that step. Our own two-to-one framing against ICS compares a broad software-detection count to a narrow protocol-based one, which is a comparison worth making and worth discounting. Trim a little for the fact that a company selling internet visibility is the one reporting a visibility explosion.
The scanner counts what it sells
Censys sells internet-wide visibility and attack-surface monitoring, and these findings are explicitly a trailer for a report it will publish later — the piece even lists which technologies the full edition will cover. That does not make the counts wrong; scan data is the one thing this vendor is genuinely positioned to produce. It does mean the choice of what to count, what to name, and which growth curve to lead with all sit inside the vendor's marketing calendar, and the outlet carrying it serves a security-buyer audience.
Trust the trend, not the decimals
We are confident that public exposure of AI tooling is growing fast and that two widely deployed open-source components have exploited flaws — the catalog entries settle that much. We are much less confident in any specific figure: single scanner, single outlet, unpublished report, no methodology, and derived comparisons that depend on populations defined differently from each other. A second scan or the full report would move this materially in either direction.