PulseAugur
中
实时 03:49:21
English(EN) 🤖 CVE-2026-64849 (CVSS 9.3): unauthenticated SSRF in MLflow (< 3.15.0) exploited in the wild to exfiltrate cloud credentials via metadata endpoints. Scans began

关键 MLflow SSRF 漏洞 (CVE-2026-64849) 正在被积极利用

在 MLflow(一个用于管理机器学习生命周期的平台)中发现了一个关键的服务器端请求伪造 (SSRF) 漏洞,即 CVE-2026-64849。该漏洞的 CVSS 评分为 9.3,无需身份验证,允许攻击者通过访问内部资源和元数据端点来窃取云凭证。野外利用已被证实,已有积极的扫描和概念验证利用,该漏洞已被添加到 CISA 已知漏洞利用目录中。 AI

影响 MLflow 中存在的这一关键漏洞可能导致 AI/ML 运营中广泛的凭证盗窃和系统泄露。

排序理由 该集群报告了一个特定的漏洞及其在广泛使用的机器学习平台中的利用情况。

在 Mastodon — mastodon.social 阅读 →

AI 生成摘要 · Google Gemini · 来自 2 个来源。 我们如何撰写摘要 →

关键 MLflow SSRF 漏洞 (CVE-2026-64849) 正在被积极利用

本文如何被排名

Signal score
0 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
该集群报告了一个特定的漏洞及其在广泛使用的机器学习平台中的利用情况。
Source corroboration
2 independent sources
Multiple independent publishers reporting the same story raises confidence that it's real and newsworthy.
Topics
infra, other
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
50 days old
Aged out of breaking-news scoring windows; ranking reflects the durable signal from the full source set.

完整方法见我们的编辑标准。

报道来源 [2]

  1. Mastodon — mastodon.social TIER_1 English(EN) · stemshop ·

    🚨 CVE-2026-64849 — 严重 MLflow SSRF CVSS 9.3 • 无需身份验证 • 公开 PoC 可用 • 已发布 Nuclei 模板 • 已确认正在积极利用

    🚨 CVE-2026-64849 — Critical MLflow SSRF CVSS 9.3 • No authentication required • Public PoC available • Nuclei template released • Active exploitation confirmed • Added to CISA KEV. The flaw can expose internal resources and potentially leak AWS/Azure/GCP cloud credentials. https:…

  2. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    🤖 CVE-2026-64849 (CVSS 9.3): MLflow (< 3.15.0) 中存在未经身份验证的 SSRF,已被野外利用以通过元数据端点窃取云凭证。扫描已开始

    🤖 CVE-2026-64849 (CVSS 9.3): unauthenticated SSRF in MLflow (< 3.15.0) exploited in the wild to exfiltrate cloud credentials via metadata endpoints. Scans began hours after the Aug 17 disclosure; bypasses prior fixes via redirect handling. Also CVE-2026-25895 (CVSS 9.5): path tra…