August 18, 2026
- MLflow CVE-2026-64849 was exploited within hours of CVE assignment. According to watchTowr, attackers are probing cloud-hosted MLflow deployments for the unauthenticated SSRF and attempting to extract credentials and secrets. All releases before MLflow 3.15.0 are affected, making credential review and compromise hunting important alongside patching. · Vulnerabilities & Exploits
in Three Fast-Moving Flaws Put GitLab and AI Infrastructure on Alert