U.S. CISA adds an MLflow flaw to its Known Exploited Vulnerabilities catalog

2026-08-20T14:51:38Ze3d3cf61f38badf392e4dcbe346ee4bc85521a21538b8a4ec0b1931c7eed21ec
CVE-2026-19478CVE-2026-33824CVE-2026-64849Apple-macOSCISA-KEVDahuaGitLabGraphQLIoTIranMLflowMacSync-StealerMicrosoft-IKEMicrosoft-SharePointSSRFStripeVMware-vCenterWordPresscamera-compromisecredential-theftcyber-espionagedata-breachknown-exploited-vulnerabilitymalware-deliveryransomwaresecrets-exposuresurveillance-evasionvulnerability

What happened

Security news covers actively exploited and critical vulnerabilities in MLflow, GitLab, Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE; major cybercrime and espionage campaigns; compromise of thousands of WordPress sites and Dahua cameras; Mac malware targeting credentials and wallets; exposed Stripe API keys; and large-scale personal-data breaches.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
e3d3cf61f38badf392e4dcbe346ee4bc85521a21538b8a4ec0b1931c7eed21ec
Enrichment time
2026-08-20T14:51:38Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.