(MLflow, CVE-2026-64849, August 2026) By Pablo Bleck, Engineering Manager & Software Engineer, ActiveState MLflow shipped its webhook API open by default across a platform with more than 30 million monthly downloads, and a CISA listing turned that unauthenticated endpoint into a 14-day deadline. The questions that would have caught it earlier are the ones most PR reviews skip under deadline pressure. TL;DR CISA added CVE-2026-64849, an unauthenticated SSRF bypass in MLflow's webhook system, to its Known Exploited Vulnerabilities catalog, landing it in BOD 26-04's 14-day remediation tier for federal agencies. MLflow's default tracking server configuration shipped the webhook API open by default, part of a platform with more than 30 million monthly downloads; the flaw let attackers reach internal, loopback, and cloud-metadata endpoints and steal cloud credentials, including AWS IAM keys. MLflow 3.15.0 fixes the flaw, but the patch is the easy part; the expensive part is ...
CISA's 2026 SBOM Minimum Elements Update Turns "We Have One" Into the Wrong Answer TL;DR CISA's updated SBOM minimum elements now explicitly cover AI products alongside conventional, open source, and software-as-a-service products. New required fields include component hashes, licenses, SBOM-generation context, and the name of the tool used to produce it. Close to 30% of code shipping today is AI-generated, and that pace outruns any manual process built to review a bill of materials by hand. An SBOM built to the prior minimum elements no longer supports the same "we have one" answer in a board meeting, an audit, or a filing. The open question is whether an SBOM would hold up if someone with subpoena power read it, not merely whether one exists. A CFO reading a disclosure document asks whether it still matches the standard the market expects of it, not whether it matched that standard on the day it was filed. A CISO reading a software bill of materials asks...