← Back to the live CVE advisory feed

CVE-2026-96775: MLflow

Severity
8.8 (HIGH)
Vendor
MLFLOW
Affected versions
2.0
Patch status
Unknown
Published
2026-09-23T17:17:25.407
Modified
2026-09-23T18:17:12.323

Why it matters

High-severity vulnerability requiring prioritized review.

Recommended admin actions

  • Review and patch based on exposure, asset criticality, and business impact.
  • Treat internet-facing systems as higher priority.

Technical summary

MLflow's dspy flavor, versions >= 2.0, applies the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control only when the model_path ends in .pkl, which allows a remote attacker to execute arbitrary code via a crafted MLmodel artifact.

CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.

VULNERABILITY PULSE

LAST UPDATED: SEP 24, 2026 08:00 AM UTC
446 RECORDS
SECURE FEED ACTIVE
AFFECTED PRODUCT ACTION
CVE-2026-59167
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
10
CRITICAL
VIEW RECORD
CVE-2026-86708
ManageEngine Applications Manager
Reporter: 0FC0942C-577D-436F-AE8E-945763C79B02
10
CRITICAL
VIEW RECORD
CVE-2026-19599
Product identification pending
Reporter: 0FC0942C-577D-436F-AE8E-945763C79B02
9.9
CRITICAL
VIEW RECORD
CVE-2026-77602
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.9
CRITICAL
VIEW RECORD
CVE-2026-84474
Product identification pending
Reporter: SECALERT
9.9
CRITICAL
VIEW RECORD
CVE-2026-84502
Product identification pending
Reporter: SECALERT
9.9
CRITICAL
VIEW RECORD
CVE-2026-84719
Product identification pending
Reporter: SECALERT
9.9
CRITICAL
VIEW RECORD
CVE-2026-89078
Product identification pending PATCH
Reporter: CVE
9.9
CRITICAL
VIEW RECORD
CVE-2026-93577
Product identification pending PATCH
Reporter: CVE
9.9
CRITICAL
VIEW RECORD
CVE-2026-76183
Product identification pending PATCH
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-86248
Product identification pending PATCH
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-96276
Product identification pending
Reporter: SECALERT
9.8
CRITICAL
VIEW RECORD
CVE-2025-63564
Product identification pending
Reporter: CVE
9.8
CRITICAL
VIEW RECORD
CVE-2026-6721
Product identification pending
Reporter: PSIRT
9.8
CRITICAL
VIEW RECORD
CVE-2026-6730
Product identification pending
Reporter: PSIRT
9.8
CRITICAL
VIEW RECORD
CVE-2026-6928
Product identification pending
Reporter: PSIRT
9.8
CRITICAL
VIEW RECORD
CVE-2026-18467
Paytium: Mollie payment forms & donations
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-85724
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.6
CRITICAL
VIEW RECORD
CVE-2026-87898
Plesk extension "Site Import" PATCH
Reporter: SUPPORT
9.4
CRITICAL
VIEW RECORD
CVE-2026-87899
cPanel PATCH
Reporter: SUPPORT
9.4
CRITICAL
VIEW RECORD
CVE-2026-87900
WP Toolkit for cPanel PATCH
Reporter: SUPPORT
9.4
CRITICAL
VIEW RECORD
CVE-2026-96560
Product identification pending
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-18872
Product identification pending
Reporter: PSIRT
9.3
CRITICAL
VIEW RECORD
CVE-2026-95848
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.3
CRITICAL
VIEW RECORD
CVE-2026-96754
Product identification pending PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-96755
Product identification pending
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-96757
Product identification pending PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-96758
Product identification pending PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-96759
Product identification pending PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-95601
Product Filter by WBW PATCH
Reporter: AUDIT
9.3
CRITICAL
VIEW RECORD
CVE-2026-96770
s2s-proxy
Reporter: SECURITY
9.3
CRITICAL
VIEW RECORD
CVE-2026-93352
Product identification pending PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-96891
DIR-825
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-96756
Product identification pending PATCH
Reporter: DISCLOSURE
9.2
CRITICAL
VIEW RECORD
CVE-2026-63132
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.2
CRITICAL
VIEW RECORD
CVE-2026-67404
rabbitmq-server PATCH
Reporter: SECURITY-ADVISORIES
9.2
CRITICAL
VIEW RECORD
CVE-2026-97055
signoz PATCH
Reporter: DISCLOSURE
9.2
CRITICAL
VIEW RECORD
CVE-2026-86350
Product identification pending PATCH
Reporter: SECURITY
9.1
CRITICAL
VIEW RECORD
CVE-2026-86246
Product identification pending PATCH
Reporter: SECURITY
9.1
CRITICAL
VIEW RECORD
CVE-2026-75884
Product identification pending
Reporter: SECALERT
9.1
CRITICAL
VIEW RECORD
CVE-2026-67231
rabbitmq-server PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-91798
Foxit PDF Editor
Reporter: 14984358-7092-470D-8F34-ADE47A7658A2
8.8
HIGH
VIEW RECORD
CVE-2026-91800
Foxit PDF Editor
Reporter: 14984358-7092-470D-8F34-ADE47A7658A2
8.8
HIGH
VIEW RECORD
CVE-2026-91803
Foxit PDF Editor
Reporter: 14984358-7092-470D-8F34-ADE47A7658A2
8.8
HIGH
VIEW RECORD
CVE-2026-91813
Foxit PDF Editor
Reporter: 14984358-7092-470D-8F34-ADE47A7658A2
8.8
HIGH
VIEW RECORD
CVE-2026-96455
Reachy Mini
Reporter: REEFS
8.8
HIGH
VIEW RECORD
CVE-2026-14913
ManageEngine OpManager
Reporter: 0FC0942C-577D-436F-AE8E-945763C79B02
8.8
HIGH
VIEW RECORD
CVE-2026-75825
Product identification pending
Reporter: 0FC0942C-577D-436F-AE8E-945763C79B02
8.8
HIGH
VIEW RECORD
CVE-2026-76978
ManageEngine OpManager
Reporter: 0FC0942C-577D-436F-AE8E-945763C79B02
8.8
HIGH
VIEW RECORD
CVE-2026-86677
ManageEngine Applications Manager
Reporter: 0FC0942C-577D-436F-AE8E-945763C79B02
8.8
HIGH
VIEW RECORD
CVE-2026-86678
ManageEngine Applications Manager
Reporter: 0FC0942C-577D-436F-AE8E-945763C79B02
8.8
HIGH
VIEW RECORD
CVE-2026-96275
Product identification pending
Reporter: SECALERT
8.8
HIGH
VIEW RECORD
CVE-2026-18490
Product identification pending
Reporter: PSIRT
8.8
HIGH
VIEW RECORD
CVE-2026-95847
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-96775
MLflow
Reporter: CRET
8.8
HIGH
VIEW RECORD
CVE-2026-96804
MLflow
Reporter: CRET
8.8
HIGH
VIEW RECORD
CVE-2026-77601
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-80379
Product identification pending
Reporter: PSIRT
8.8
HIGH
VIEW RECORD
CVE-2026-80412
Product identification pending
Reporter: PSIRT
8.8
HIGH
VIEW RECORD
CVE-2026-80425
Product identification pending
Reporter: PSIRT
8.8
HIGH
VIEW RECORD
CVE-2026-80423
Product identification pending
Reporter: PSIRT
8.8
HIGH
VIEW RECORD
CVE-2026-81537
Product identification pending
Reporter: PSIRT
8.8
HIGH
VIEW RECORD
CVE-2026-86583
Import and export users and customers
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-70125
Microsoft 365 Apps for Enterprise
Reporter: SECURE
8.8
HIGH
VIEW RECORD
CVE-2026-55610
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-96673
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-95842
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-95843
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-95844
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-95845
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-95846
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-82368
Product identification pending PATCH
Reporter: SIRT
8.7
HIGH
VIEW RECORD
CVE-2026-68492
Product identification pending PATCH
Reporter: SUPPORT
8.7
HIGH
VIEW RECORD
CVE-2026-82405
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-84683
Product identification pending
Reporter: SECALERT
8.7
HIGH
VIEW RECORD
CVE-2026-84691
Product identification pending
Reporter: SECALERT
8.7
HIGH
VIEW RECORD
CVE-2026-15027
Product identification pending
Reporter: TWCERT
8.6
HIGH
VIEW RECORD
CVE-2026-93349
Product identification pending
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-96656
Product identification pending PATCH
Reporter: 9119A7D8-5EAB-497F-8521-727C672E3725
8.6
HIGH
VIEW RECORD
CVE-2026-90901
Product identification pending
Reporter: SECURITY
8.6
HIGH
VIEW RECORD
CVE-2026-90904
Product identification pending
Reporter: SECURITY
8.6
HIGH
VIEW RECORD
CVE-2026-86064
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.6
HIGH
VIEW RECORD
CVE-2026-82369
Product identification pending PATCH
Reporter: SIRT
8.6
HIGH
VIEW RECORD
CVE-2026-82370
Product identification pending PATCH
Reporter: SIRT
8.6
HIGH
VIEW RECORD
CVE-2026-97152
Product identification pending PATCH
Reporter: CVE
8.6
HIGH
VIEW RECORD
CVE-2026-79310
Product identification pending
Reporter: CVE
8.5
HIGH
VIEW RECORD
CVE-2026-75131
Product identification pending PATCH
Reporter: DISCLOSURE
8.5
HIGH
VIEW RECORD
CVE-2026-76086
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.5
HIGH
VIEW RECORD
CVE-2026-76648
Product identification pending
Reporter: SECALERT
8.5
HIGH
VIEW RECORD
CVE-2026-93527
Live Copy Paste for Elementor PATCH
Reporter: AUDIT
8.5
HIGH
VIEW RECORD
CVE-2026-93773
Mollie Forms PATCH
Reporter: AUDIT
8.5
HIGH
VIEW RECORD
CVE-2026-94124
WP EasyCart PATCH
Reporter: AUDIT
8.5
HIGH
VIEW RECORD
CVE-2026-5695
Administration panel
Reporter: CVE-COORDINATION
8.4
HIGH
VIEW RECORD
CVE-2026-82409
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.4
HIGH
VIEW RECORD
CVE-2026-97151
Product identification pending PATCH
Reporter: CVE
8.4
HIGH
VIEW RECORD
CVE-2026-95626
tauri
Reporter: REEFS
8.3
HIGH
VIEW RECORD
CVE-2026-96454
Pake
Reporter: REEFS
8.2
HIGH
VIEW RECORD
CVE-2026-96599
Product identification pending
Reporter: DISCLOSURE
8.2
HIGH
VIEW RECORD
CVE-2026-19179
Product identification pending
Reporter: PSIRT
8.2
HIGH
VIEW RECORD
CVE-2026-76087
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.2
HIGH
VIEW RECORD

About the Vulnerability Pulse CVE Feed

The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.

How to Use the CVE Advisory Tracker

Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.

What Is a CVE Advisory?

A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.

CVE Analysis & Writeups

For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.