CVE-2026-72649: Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote code execution via Object Injection (CAPEC-586). A specially crafted trained model art...

Added to the CISA Known Exploited Vulnerabilities catalog on 01 Sep 2026. Vendor: AI/ML. Product: machine learning. CVSS score: 8.8.

Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote code execution via Object Injection (CAPEC-586). A specially crafted trained model artifact could cause attacker-controlled logic to execute with a materially broader system-call surface...

Required action: Review and patch if applicable to your AI infrastructure.