| 1. Claude Opus 5 (High) |
| 2. Claude Opus 5 (Max) |
| 3. Claude Fable 5 (High) |
| 4. Kimi K3 (Max) |
| 5. GPT 5.6 Sol (xHigh) |
The BriefMLflow is a free tool many companies use to track and manage their AI models. On August 19 the US cyber agency CISA confirmed that attackers are actively using a critical flaw in it (CVE-2026-64849) to reach into servers and pull out cloud passwords for AWS, Azure and Google, with no login needed. Any MLflow older than version 3.15.0 that can be reached from the internet is exposed right now. This matters to ordinary businesses, not just AI labs: AI tooling is becoming normal infrastructure, and it needs the same patching discipline as everything else on the network.
Level UpBookmark CISA's Known Exploited Vulnerabilities catalog and make checking it part of your patch routine this week. It is a free, searchable list of the security holes attackers are actually using in the wild, not just the theoretical ones. Search it for every AI or ML tool you or your clients self-host, MLflow included. Ten minutes against that list tells you what truly cannot wait. The CISA Known Exploited Vulnerabilities catalog, the patch-first list to check