LIVE · cybersecurity feed
Live wire
vendor1 exploited in the wild

Lfprojects

15 CVEs published in the last four months. Exploited flaws first.

Critical4
High11
Medium0
Exploited (KEV)1

Patch these first

CVECVSSSeverityProductSummaryPublished
CVE-2026-64849exploited9.3criticalmlflowMLflow is an open source AI engineering platform for agents, large language models, and machine learning models.19d ago

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-26119.6criticalmlflowIn MLflow version 3.9.0, the MLflow Assistant feature introduced improper origin validation in its /ajax-api endpoi109d ago
CVE-2026-64849exploited9.3criticalmlflowMLflow is an open source AI engineering platform for agents, large language models, and machine learning models.19d ago
CVE-2025-150319.1criticalmlflowA vulnerability in MLflow's pyfunc extraction process allows for arbitrary file writes due to improper handling of171d ago
CVE-2026-26519criticalmlflowA vulnerability in MLflow versions <=3.10.1.dev0 allows unauthorized access to multipart upload (MPU) endpoints whe103d ago
CVE-2025-142878.8highmlflowA command injection vulnerability exists in mlflow/mlflow versions before v3.7.0, specifically in the `mlflow/sage173d ago
CVE-2026-26528.6highmlflowA vulnerability in mlflow/mlflow versions 3.9.0 and earlier allows unauthenticated access to certain FastAPI routes114d ago
CVE-2026-81478.1highmlflowIn MLflow versions prior to 3.14.0, when running with authentication enabled, the trace API endpoints lack proper a65d ago
CVE-2026-599508.1highmcp python sdkThe MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP).52d ago
CVE-2026-41377.8highmlflowIn mlflow/mlflow versions prior to 3.11.0, the `get_or_create_nfs_tmp_dir()` function in `mlflow/utils/file_utils.p110d ago
CVE-2026-40357.7highmlflowA vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of environment variables in AI 94d ago
CVE-2026-528707.6highmcp python sdkThe MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP).52d ago
CVE-2026-26147.5highmlflowA vulnerability in the `_create_model_version()` handler of `mlflow/server/handlers.py` in mlflow/mlflow versions 3117d ago
CVE-2026-528697.1highmcp python sdkThe MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP).52d ago
CVE-2026-23937.1highmlflowA Server-Side Request Forgery (SSRF) vulnerability exists in MLflow versions prior to 3.9.0.117d ago
CVE-2026-332527.1highmcp go sdkThe Go MCP SDK used Go's standard encoding/json.166d ago

Filter the full tracker by Lfprojects