NVD disclosure day

Published threat advisories for March 30, 2026

CVE advisoryKnown Exploit

CVE-2026-3502

TrueConf Client could allow an external attacker to gain control of your computer.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A flaw in the TrueConf Client update process allows an external attacker to intercept connections and install malicious software. This provides the attacker full control over the computer, creating a critical risk of data theft and unauthorized system access.

• CISA KEV

CVE advisoryCRITICAL

CVE-2025-15379

MLflow Command Injection Vulnerability in Model Serving

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A command injection vulnerability exists in MLflow model serving. An attacker could execute arbitrary commands on systems deploying models by supplying a malicious model artifact. This could lead to unauthorized command execution on the host system where the model is served.