Latest Cybersecurity News and IT Security Insights
Stay informed about emerging threats, practical protection strategies and innovations in vulnerability management. Benefit from the expertise of the Greenbone specialists and strengthen your IT security.
Subscribe to the Newsletter Now



CVE-2026-64849: SSRF Flaw in MLflow Actively Exploited
BlogCVE-2026-64849 (CVSS 9.3, EPSS ≥ 95th pctl) is a critical-severity unauthenticated full-read server-side request forgery (SSRF) flaw [CWE-918] in MLflow webhook delivery. The CVE affects all versions prior to 3.15.0. The root cause is flawed redirect handling and DNS rebinding. The flaw is exploited by bypassing the _validate_webhook_url protections in the default MLflow Tracking Server […]
The Cyber Resilience Act at Two Weeks: What’s Actually Ready, and What Isn’t
BlogTwo weeks before Article 14 reporting becomes mandatory, the infrastructure behind it is still under construction. The Commission’s guidance is approved but not yet formally in force. The reporting platform is in testing, not live. Not one harmonised standard has a citation in the Official Journal. Each of those gaps puts more weight on the […]
CVE-2026-19478: GitLab CE/EE GraphQL Unauthenticated Flaw Actively Exploited
BlogGitLab has released fixes for CVE-2026-19478 (CVSS 9.4, EPSS 0.7% (51st percentile)), a critical-severity code injection flaw [CWE-94]. The vulnerability affects the GraphQL directive in GitLab Community Edition (CE) and Enterprise Edition (EE). According to GitLab, the flaw can allow an unauthenticated attacker to remotely modify or delete public projects and user data under certain […]