SPOJENO PŘES CVE KEV ✓ EPSS 0.16
CISA warns of hackers exploiting critical MLflow vulnerability
The Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies that threat actors are now exploiting a critical vulnerability in the MLflow open-source AI engineering platform. [...]
MLflow veřejná správa US CA
CVE v události 1
| CVE | hodnocení | KEV | EPSS |
|---|---|---|---|
| CVE-2026-64849 | 9.3 3.1 · GitHub_M | KEV ✓ | 0.16 |
Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE.
Jak se o tom psalo 4
-
· BleepingComputer US nadpis události
CISA warns of hackers exploiting critical MLflow vulnerability
The Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies that threat actors are now exploiting a critical vulnerability in the MLflow open-source AI engineering platform. [...]
-
· Cyber Centre Kanada CA
MLflow security advisory (AV26-832)
Serial Number: AV26-832Date: August 19, 2026 As of August 17, 2026, MLflow is affected by vulnerabilities in the following product: MLflow Prior to 3.15.0 On August 19, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-64849 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Release v3.15.0 · mlflow/mlflow · GitHub…
-
· CISA Advisories US
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-64849 MLflow Server-Side Request Forgery Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian…
-
· CISA KEV US
MLflow Server-Side Request Forgery Vulnerability (CVE-2026-64849)
CISA added CVE-2026-64849 to the Known Exploited Vulnerabilities catalog. Affected product: MLflow MLflow. Remediation due date: 2026-09-02.