The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical server-side request forgery (SSRF) vulnerability in MLflow, tracked as CVE-2026-64849, to its Known Exploited Vulnerabilities (KEV) catalog. This designation indicates that the flaw is actively being exploited in the wild.
The vulnerability, which carries a CVSS score of 9.3, affects MLflow versions prior to 3.15.0. MLflow is an open-source platform widely used for managing machine learning and AI development workflows, with tens of millions of monthly downloads.
Exploitation of CVE-2026-64849 does not require authentication, allowing a remote attacker to make requests from an exposed MLflow server to internal services. This capability includes targeting cloud metadata endpoints, which can lead to the exposure and theft of temporary cloud credentials and other sensitive secrets.
Cybersecurity firm watchTowr reported observing active exploitation of this unauthenticated SSRF vulnerability. The firm's global honeypot network, Attacker Eye, detected widespread scanning for exposed MLflow instances within hours of the CVE being assigned on August 17, 2026. These scans included attempts against cloud-hosted instances, indicating attackers are specifically seeking to access cloud metadata services.
The inclusion of CVE-2026-64849 in CISA's KEV catalog mandates that federal civilian executive branch agencies patch their systems against this vulnerability within a specified timeframe to protect against ongoing threats.






