Actively exploited MLflow SSRF can reach cloud metadata
An unauthenticated MLflow webhook test can follow redirects into internal services or cloud metadata endpoints and return their responses.
9 of 9 advisories
An unauthenticated MLflow webhook test can follow redirects into internal services or cloud metadata endpoints and return their responses.
A critical double-free flaw in the Windows IKE service can allow an unauthenticated network attacker to execute code on a reachable system.
A critical JWT authentication weakness can let an unauthenticated network attacker bypass SharePoint security controls and access protected data.
A critical directory-traversal flaw in the vCenter Syslog server can allow an unauthenticated network attacker to execute arbitrary code.
A critical state-management flaw can let a network attacker authenticate to macOS Screen Sharing without valid credentials.
An unauthenticated SQL-injection path can lead to Metabase administrator access, exposed database credentials, and data theft.
CISA reports that unsafe deserialization in the TeamCity agent polling protocol can permit unauthenticated remote code execution.
CISA says default Langflow deployments may permit unauthenticated attackers to achieve full remote code execution.
| Published | Advisory | Technology | Signal | Priority |
|---|---|---|---|---|
MLflow MLflowCVE-2026-64849 | AI, Machine learning, Developer infrastructure | Known exploited | Act now | |
Microsoft Windows IKE Service ExtensionsCVE-2026-33824 | Windows, IPsec, VPN infrastructure | Known exploited | Act now | |
Microsoft SharePoint ServerCVE-2026-55040 | Collaboration, Document management, On-premises infrastructure | Known exploited | Act now | |
Broadcom VMware vCenterCVE-2026-59310 | Virtualization, Infrastructure management | Known exploited | Act now | |
Apple macOSCVE-2026-65400 | Endpoints, Remote access, macOS | Known exploited | Act now | |
Metabase MetabaseCVE-2026-72898 | Analytics, Data platforms | Active exploitation | Act now | |
JetBrains TeamCityCVE-2026-63077 | CI/CD, Developer infrastructure | Known exploited | Act now | |
IBM LangflowCVE-2026-9198 | AI, Agent workflows | Known exploited | Act now | |
Progress LoadMasterCVE-2026-8037 | Infrastructure, Load balancers | Known exploited | Act now |
Either the filters are too specific, or security has finally been solved. Probably the filters.