CVE-2026-28500: Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. In versions up to and including 1.20.1, a security control bypass exists in onnx.hub.load() due to imp...

Added to the CISA Known Exploited Vulnerabilities catalog on 18 Mar 2026. Vendor: AI/ML. Product: machine learning. CVSS score: 8.6.

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. In versions up to and including 1.20.1, a security control bypass exists in onnx.hub.load() due to improper logic in the repository trust verification mechanism. While the function is designed to warn u...

Required action: Review and patch if applicable to your AI infrastructure.