Tensoropera develops machine-learning and federated-learning platforms, with its FEDML product serving as a focal point for distributed training and model coordination across research and enterprise environments. The vendor's vulnerability footprint centers on deserialization of untrusted data, improper input validation, and path-traversal weaknesses—classes characteristic of software that accepts and processes external data streams and file paths in complex, multi-node architectures. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tensoropera over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-5536HIGH A weakness has been identified in FedML-AI FedML up to 0.8.9. Affected is the function sendMessage of the file grpc_server.py of the component gRPC server. Executing a manipulation | Apr 5, 2026 | 7.3 | 24 | NO | NO |
CVE-2026-5535MEDIUM A security flaw has been discovered in FedML-AI FedML up to 0.8.9. This impacts an unknown function of the file FileUtils.java of the component MQTT Message Handler. Performing a m | Apr 5, 2026 | 5.4 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tensoropera.
Media articles that mention a CVE ID that affects a product developed by Tensoropera — matched by CVE ID, not by vendor name.