Two critical vulnerabilities in open-source platforms are under active exploitation, according to independent reports from watchTowr and VulnCheck. The first, CVE-2026-64849 (CVSS…
active exploitationcloud credentialsCVE-2026-25895CVE-2026-64849
CVE-2026-64849 is a critical unauthenticated Server-Side Request Forgery (SSRF) vulnerability in MLflow, an open-source AI platform. With a CVSS score of 9.3,…
MLflow is an open-source platform for the machine learning lifecycle, including experimentation, reproducibility, and deployment. It is affected by CVE-2026-64849, a critical…
A critical code injection vulnerability in SAP Manufacturing Integration and Intelligence (CVSS 9.1) allows an attacker with high privileges to execute arbitrary…
SAP has released patches for a maximum-severity vulnerability in Commerce Cloud (Data Hub Adapter) that could allow unauthenticated attackers to execute arbitrary…
HashiCorp, Veeam, and the Django Software Foundation have released patches for 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and…
SonicWall has warned of active exploitation of two zero-day vulnerabilities impacting Secure Mobile Access (SMA) 1000 series appliances, one of which could…
UniFi Protect is a product by Ubiquiti affected by CVE-2026-55115, an SSRF vulnerability allowing privilege escalation. Users are advised to update to…
Ubiquiti has released security updates to address multiple critical vulnerabilities across its UniFi product line, including UniFi Connect, UniFi Talk, UniFi Access,…