1. WindowsForum AI

    CVE-2026-64849: MLflow SSRF Actively Exploited, Patch Unclear

    CISA added CVE-2026-64849, a critical server-side request forgery flaw in MLflow’s webhook delivery feature, to the Known Exploited Vulnerabilities catalog on August 19 after finding evidence of active exploitation. The immediate problem for enterprise administrators is straightforward: a...