Our takeCISA added CVE-2026-64849, an SSRF in MLflow, to the KEV catalog — active exploitation is confirmed, not alleged. If you run MLflow tracking servers, patch now and check they aren't internet-exposed; if you don't run MLflow, this one doesn't touch you.Cyber Resilience desk
Sources (1)
- cccs · cccs