CISA warns of active MLflow vulnerability exploitation by hackers
The Cybersecurity and Infrastructure Security Agency (CISA) warned on 20 August 2026 that threat actors were actively exploiting a critical vulnerability in MLflow, an open-source AI engineering platform. Federal agencies were ordered to patch the flaw after confirmed exploitation.