CISA has added CVE-2026-64849 to its Known Exploited Vulnerabilities catalogue. The entry concerns the MLflow server, a product of MLflow, and is titled “MLflow Server‑Side Request Forgery Vulnerability”. The flaw allows an attacker to send crafted requests that cause the server to reach internal or cloud metadata services and return their status and body.
The vulnerability is a server‑side request forgery (SSRF) that can be exploited over network access to the MLflow service. Successful exploitation enables the retrieval of sensitive metadata from internal networks or cloud providers, potentially leading to further compromise. It carries a CVSS v3.1 score of 9.3, rated CRITICAL, and a patch is available from the vendor.
Active exploitation has been confirmed, which is why the CVE was placed in the KEV catalogue. No known ransomware campaign has been linked to this flaw at this time. Federal civilian executive branch (FCEB) agencies must remediate the issue by 2026‑09‑02, as specified by CISA’s remediation due date.
CISA requires affected FCEB agencies to apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26‑04 Prioritizing Security Updates Based on Risk guidance and CISA’s “Forensics Triage Requirements”. They must follow applicable BOD 26‑04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26‑04 patching guidelines. All other organisations should review their exposure to MLflow and apply the available patch or vendor‑recommended mitigations promptly.
For full details, see the NVD entry at https://nvd.nist.gov/vuln/detail/CVE-2026-64849 and the CISA KEV catalogue.