www.cisa.gov 8/19/2026, 8:06:32 PM · external

CISA flags MLflow SSRF flaw CVE-2026-64849 in KEV catalog

CyberSIXT Evidence Panel
Primary Source nvd.nist.gov
CISA KEV Listed in KEV
Patch Patch Available

THE Known Exploited Vulnerabilities Catalog (KEV), maintained by CISA, is an essential resource for managing cybersecurity. It lists vulnerabilities that are actively exploited in the wild, aiding organizations in vulnerability management prioritization. The page details a specific vulnerability, CVE-2026-64849, which affects MLflow and allows for server-side request forgery, potentially compromising internal services. Organizations are urged to follow provided mitigations and CISA guidance.

The catalog is accessible in multiple formats, including CSV and JSON, and users can report new vulnerabilities for inclusion. Additionally, there are subscription options for updates.

View Primary Source Via www.cisa.gov

Article by CyberSIXT