“MLflow” — 20 distilled results

CISA warns of active MLflow vulnerability exploitation by hackers

The Cybersecurity and Infrastructure Security Agency (CISA) warned on 20 August 2026 that threat actors were actively exploiting a critical vulnerability in MLflow, an open-source AI engineering platform. Federal agencies were ordered to patch the flaw after confirmed exploitation.

Multiple critical vulnerabilities disclosed in enterprise software

Between August 3 and August 20, 2026, CISA added multiple critical vulnerabilities to its active exploitation list, including authentication bypass flaws in N-able N-central, code injection in TrueConf Server, and server-side request forgery in MLflow. CVE-2026-18577 and CVE-2026-18556 affect remote access management software, while CVE-2026-72530 and CVE-2026-72529 target enterprise conferencing infrastructure.

json:cisa-kev 41d ago · rss:cisa-advisories 41d ago

🔴 New security advisory: CVE-2026-64849 affects Lfprojects Mlflow. • Impact: Remote code execution or complete system compromise possible • Risk: Attackers can gain full control of affected systems •

🔴 New security advisory: CVE-2026-64849 affects Lfprojects Mlflow. • Impact: Remote code execution or complete system compromise possible • Risk: Attackers can gain full control of affected systems • Mitigation: Patch immediately or isolate affected systems Full breakdown: https://www.