6 min read
Vulnerabilities CVE-2026-18948 (CVSS 9.9) exploits Python dill deserialization to achieve unauthenticated RCE on Feast feature servers. CVE-2026-23537 (CVSS 9.1) allows arbitrary file writes via the /save-document endpoint. Together they expose ML pipelines to full compromise.