CVE-2026-64849: MLflow SSRF Actively Exploited — Patch to 3.15.0 Now
MLflow CVE-2026-64849 is an unauthenticated SSRF in the webhook test endpoint (CVSS 9.3), actively exploited to steal cloud IAM credentials. Patch to 3.15.0 ...
Latest tech industry news, product launches, and company announcements