← nejvýznamnější zprávy · všechny zprávy

SPOJENO PŘES CVE KEV ✓ EPSS 0.16

CISA warns of hackers exploiting critical MLflow vulnerability

The Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies that threat actors are now exploiting a critical vulnerability in the MLflow open-source AI engineering platform. [...]

Číst originál na BleepingComputer →

4 zprávy z 4 zdrojů · první 19. 8. 02:00 · poslední 20. 8. 13:06 CZ · EN/orig

MLflow veřejná správa US CA

tg: zneužíváno tg: zranitelnost tg: regulace

CVE v události 1

CVEhodnoceníKEVEPSS
CVE-2026-64849 9.3 3.1 · GitHub_M KEV ✓ 0.16

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE.

Jak se o tom psalo 4

  1. · BleepingComputer US nadpis události

    CISA warns of hackers exploiting critical MLflow vulnerability

    The Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies that threat actors are now exploiting a critical vulnerability in the MLflow open-source AI engineering platform. [...]

  2. · Cyber Centre Kanada CA

    MLflow security advisory (AV26-832)

    Serial Number: AV26-832Date: August 19, 2026 As of August 17, 2026, MLflow is affected by vulnerabilities in the following product: MLflow Prior to 3.15.0 On August 19, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-64849 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Release v3.15.0 · mlflow/mlflow · GitHub…

  3. · CISA Advisories US

    CISA Adds One Known Exploited Vulnerability to Catalog

    CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-64849 MLflow Server-Side Request Forgery Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian…

  4. · CISA KEV US

    MLflow Server-Side Request Forgery Vulnerability (CVE-2026-64849)

    CISA added CVE-2026-64849 to the Known Exploited Vulnerabilities catalog. Affected product: MLflow MLflow. Remediation due date: 2026-09-02.