Our takeCISA added CVE-2026-64849, an SSRF in MLflow, to the KEV catalog — active exploitation is confirmed, not alleged. If you run MLflow tracking servers, patch now and check they aren't internet-exposed; if you don't run MLflow, this one doesn't touch you.Cyber Resilience desk
Sources (1)
- cisa_advisories · cisa_advisories
What this means for you — Security leader:CISA added CVE-2026-64849 (MLflow SSRF) to the KEV catalog, confirming active exploitation. Federal agencies and organizations subject to BOD 22-01 must remediate within the required timeframe; all others should prioritize patching or implementing network controls if they run MLflow.
What this means for you — Lean IT orgs:If you run MLflow in your environment, this server-side request forgery flaw is confirmed exploited in the wild — update it or restrict access to it right away.
What this means for you — MSP:CISA added CVE-2026-64849 (MLflow SSRF) to the KEV catalog after confirming active exploitation. Check every client that runs MLflow and patch or block external access to it immediately.
What this means for you — Researcher:CISA added CVE-2026-64849, an MLflow Server-Side Request Forgery vulnerability, to the KEV catalog based on evidence of active exploitation.