What you need to know today.
MLflow SSRF flaw exploited; critical WordPress plugin vulns, Totolink router flaws, and Firefox sandbox escape disclosed.

A critical Server-Side Request Forgery (SSRF) vulnerability in MLflow, a popular open-source AI engineering platform, is being actively exploited in the wild. The flaw, tracked as CVE-2026-64849, affects versions 3.3.0 through 3.14.0. Attackers can exploit this vulnerability through an unauthenticated POST request to the /api/2.0/mlflow/webhooks/{id}/test endpoint. Successful exploitation allows attackers to steal cloud credentials and secrets, posing a significant risk to cloud-hosted AI and machine learning models. This vulnerability has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, underscoring its immediate threat. Patches are available in MLflow version 3.15.0. The Hacker News reported, and GovInfoSecurity noted, the active exploitation and potential for credential theft.
Multiple critical vulnerabilities have been disclosed in WordPress plugins, with several allowing unauthenticated arbitrary file uploads and code injection. CVE-2025-69129, affecting the WordPress & WooCommerce Scraper Plugin (<= 1.0.7), permits unauthenticated arbitrary file uploads. Similarly, CVE-2025-60235 (Support Ticket System for WooCommerce <= Premium) and CVE-2025-49060 (CMSSuperHeroes Wastia < 1.1.3) also suffer from unrestricted file uploads, potentially allowing for web shell deployment. Other critical flaws include code injection in Beplusthemes Alone (<= 7.8.3) via CVE-2025-60206, and multiple instances of unauthenticated PHP object injection in various plugins such as Plumbing (<= 1.6) (CVE-2025-69127), Reisen (<= 1.4.1) (CVE-2025-69111), Hot Coffee (<= 1.7) (CVE-25-69108), and ThemeREX Addons (<= 2.36.1.1) (CVE-2025-60205). Privilege escalation vulnerabilities were also found in Capella (<= 2.5.5) (CVE-2025-15689) and Support Ticket Management System (<= 1.9) (CVE-2025-69179). These vulnerabilities, detailed in Wordfence's and other reports, highlight the ongoing risks associated with popular WordPress ecosystem components.
Critical vulnerabilities have been identified in Totolink routers, specifically affecting the A3002MU model running firmware version 1.0.0-B20230403.1455. CVE-2026-105285 targets the QoS Rule Handler component, where manipulation of arguments in the /boafrm/formIpQoS file can lead to security weaknesses. Additionally, CVE-2026-105284 impacts the Authentication Check component, with a weakness in the /bin/boa file allowing for improper authorization. Both vulnerabilities carry a CVSS score of 10.0, indicating a severe risk of exploitation. While specific exploitation details are limited, these flaws in network infrastructure devices like routers can have widespread implications for network security and data integrity.
A critical vulnerability in Ahsay's backup solution, AhsayCBS, up to version 10.3.2, could allow for operating system command injection. Tracked as CVE-2026-105134, the flaw resides in the Replication Receiver component, specifically within the UpdateReceivers.do endpoint. By manipulating the 'random' argument, an attacker can potentially execute arbitrary commands on the underlying operating system, leading to a complete compromise of the affected server. This vulnerability poses a significant risk to data integrity and confidentiality for organizations relying on Ahsay for their backup needs.
Rogue Wave's Perforce P4 Search container images, prior to version 2026.4.2, contain a vulnerability where the service authentication token can be reset to a publicly documented default value. CVE-2026-100103 allows an unauthenticated attacker with network access to obtain the highest application privileges. This could lead to a full compromise of the Perforce environment, impacting the security and availability of version-controlled assets. Users are advised to update to version 2026.4.2 or later to mitigate this risk.
Mozilla developers have identified a critical vulnerability in Firefox, CVE-2025-2857, which bears similarities to a recently disclosed Chrome sandbox escape. The flaw lies within the Inter-Process Communication (IPC) code, where a compromised child process could trick the parent process into returning an unintentionally powerful handle. This could potentially lead to a sandbox escape and allow attackers to execute arbitrary code on the user's system. While specific exploitation details are still emerging, this vulnerability highlights the ongoing challenges in securing complex browser architectures.