Monday, March 30, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Monday's vulnerability disclosures are dominated by critical flaws in MLflow and OpenClaw, with a perfect CVSS 10.0 remote code execution vulnerability in MLflow (CVE-2025-15379) and five additional critical OpenClaw vulnerabilities scoring 9.8-9.9. The day's 68 disclosed CVEs include 7 critical and 61 high-priority issues, with high-severity volume dropping 38% from the prior day while critical counts held steady. Eight vulnerabilities have confirmed active exploitation, targeting Apple products, Zimbra Collaboration Suite, Craft CMS, Laravel Livewire, Langflow, and Aquasecurity Trivy. Attack patterns center on remote code execution and authentication bypass across both ML/AI platforms and widely deployed enterprise software. No patches are currently available for any of the disclosed vulnerabilities, requiring defenders to rely on compensating controls and network-level mitigations.

  • MLflow CVE-2025-15379 scores a perfect CVSS 10.0 β€” assess exposure in any ML pipeline environments immediately
  • 7 critical CVEs disclosed (unchanged from prior day), with 5 affecting OpenClaw at CVSS 9.8-9.9
  • 61 high-priority CVEs, down 38% from the prior day's 98
  • Active exploitation confirmed across Apple products, Zimbra ZCS, Craft CMS, Laravel Livewire, Langflow, and Trivy
  • Patch availability stands at 0% β€” no vendor fixes released for any of the 68 disclosed vulnerabilities
  • 8 actively exploited vulnerabilities span enterprise collaboration, CMS, and AI/ML tooling categories

Immediate action: Organizations running MLflow, OpenClaw, Apple products, Zimbra, Craft CMS, Laravel Livewire, Langflow, or Trivy should audit exposure immediately and apply network segmentation or access restrictions as interim mitigations. With zero patches currently available, prioritize monitoring for exploitation indicators and restrict public-facing access to affected services until vendor fixes are released.

How to read this brief

CVSS score (e.g. 9.1) β€” severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability β€” how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical β€” how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges β€” the access they need first. No privileges means no login required.
  • No interaction / User interaction β€” whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale β€” β€œNetwork Β· No privileges Β· No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited β€” confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS Β· Nth percentile β€” FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% β€” a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

πŸ’‘ Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation