Curated Cyber Threat Intelligence
Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports
Filtered Reports
2 / 2 results
criticalbug_reportVulnerabilitybug_reportVulnerability
CISA: Critical MLflow SSRF flaw (CVE-2026-64849) exploited in the wild
MLflow open-source AI engineering platform, all versions prior to 3.15.0. Default MLflow Tracking Server deployments without authentication are vulnerable.
MLflow20 Aug · 09:06 UTC
criticalbug_reportVulnerabilitybug_reportVulnerability
MLflow SSRF and FUXA path traversal flaws under active exploitation
MLflow versions < 3.15.0 (CVE-2026-64849, CVSS 9.3) and FUXA versions <= 1.2.9 (CVE-2026-25895, CVSS 9.5). MLflow is an open-source AI platform; FUXA is open-source SCADA/HMI software for industrial automation.
MLflow18 Aug · 15:44 UTC