⌁AI·CYBER·BRIEF▌

#CVE-2026-96775

Vulnerabilities7 min read

MLflow: two flaws let a crafted model run code even with pickle loading off

CERT/CC published two CVEs in MLflow's dspy and statsmodels model loaders. The statsmodels fix shipped in 3.15.0; the dspy gap is still open in the current release.

Supply ChainCVE-2026-96775CVE-2026-96804