The rapid adoption of AI tools and LLMs is creating new, high-risk attack surfaces for organizations that leave these tools exposed to the internet, whether intentionally or accidentally. New data from the forthcoming 2026 Censys State of the Internet Report shows that exposures of AI/LLM tools has risen by more than 60 percent over the last nine months, with more than 294,000 distinct IP addresses now exposing at least one of 43 detected AI/LLM tools to the public internet.

The proliferation of exposed infrastructure is compounded by the fact that the most widely adopted tools often carry significant security risks. Security researchers have found that the highest-risk products are among the fastest growing in the current landscape.

  • Langflow: This framework saw 169 percent growth over the past nine months and has 18 published CVEs between 2024 and 2026, 14 of which have a CVSS score above 8.0. With four entries in CISA's Known Exploited Vulnerabilities (KEV) catalog and multiple unauthenticated remote code execution (RCE) vulnerabilities, any internet-facing instance of the tool could be a target.
  • LiteLLM: The usage of this unified LLM proxy nearly doubled—growing 97 percent—in the same nine-month period. It is currently linked to an actively exploited pre-auth SQL injection bug (CVE-2026-42208) that’s in the CISA KEV catalog. Because LiteLLM acts as a central proxy, a single compromise can expose the API keys for every upstream model provider configured within the environment.

"The floor has definitely been lowered for attackers and it’s really dangerous."

“A lot of this AI infrastructure shouldn’t be out there on the public internet, given the types of control these tools have and the access they have to stuff in these environments. The people deploying these tools are not security pros or asking for security reviews on their processes,” said Emily Austin, principal security researcher on the Censys ARC team.

The new data is a snapshot of a threat landscape that is changing at an unprecedented rate, providing a window into what is likely to become a much more complex and ungovernable section of the internet. Broad use of AI tooling and LLMs is still in its infancy, and as with any new technology, the attacks on these tools will only improve over time. 

“AI is raising the ceiling for attackers. It;s also lowered the floor. We’re allowing threat actors access to so much and you’ve got all of your stuff out on the public internet in an open directory,” Austin said. 

“It’s gonna get more intense before it gets less intense. We;re seeing an explosion of tooling.”

The trend toward exposing these management and automation tools on the public internet is part of a broader shift in how internet-facing infrastructure is managed and secured. As organizations rush to integrate generative AI, the speed of deployment often outpaces security controls, leaving misconfigured or unpatched management interfaces accessible to scanners.

Security teams should prioritize clear visibility into their internet-facing AI footprint. Because these tools often sit at the intersection of enterprise data and external model providers, they are increasingly becoming attractive targets for attackers seeking initial access, credential theft, or the ability to manipulate data pipelines. 

“So much of this is rinse and repeat like we’ve seen with other things like cloud platforms. The floor has definitely been lowered for attackers and it’s really dangerous,” Austin said.