A critical pre-authentication SQL injection vulnerability (CVE-2026-42208) in LiteLLM, the popular open-source LLM proxy gateway, was actively exploited just 36 hours after its advisory was published to the GitHub Advisory Database. The Sysdig Threat Research Team captured targeted exploitation attempts that enumerated LiteLLM's three highest-value PostgreSQL tables — virtual API keys, stored provider credentials, and environment variables — using precise Prisma-generated table names, indicating the attacker had prior knowledge of the schema. The vulnerability affects versions 1.81.16 through 1.83.6 and is fixed in v1.83.7. No confirmed successful extraction or authenticated follow-on was observed, but defenders are urged to patch immediately, rotate all credentials, and treat any internet-exposed instance during the vulnerability window as compromised. The incident highlights that AI gateways aggregate cloud-grade credentials and represent a high-value target requiring tier-1 security treatment.