type: cve ยท created: 2026-08-20 ยท updated: 2026-08-20 ยท tags: [cve, mlflow, ssrf, kev, exploited] ยท confidence: high ยท severity: high ยท affected_sectors: [technology, ai-ml] ยท au_impact: true
CVE-2026-64849
CVE-2026-64849 is a Server-Side Request Forgery (SSRF) vulnerability in MLflow, added to the CISA Known Exploited Vulnerabilities (KEV) catalogue on 19 August 2026, signalling confirmed in-the-wild exploitation of the machine-learning orchestration platform.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-64849 |
| Type | Server-Side Request Forgery (SSRF) |
| Product | MLflow (widely used for ML workflows) |
| KEV added | 2026-08-19 (federal 14-day patch cadence) |
| Source | CISA โ Tier 1/4 |
The add continues the federal 14-day patch-file cadence following the larger four-vulnerability batch earlier that week, and puts internet-exposed MLflow deployments on notice.