Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-08-20 ยท updated: 2026-08-20 ยท tags: [cve, mlflow, ssrf, kev, exploited] ยท confidence: high ยท severity: high ยท affected_sectors: [technology, ai-ml] ยท au_impact: true

CVE-2026-64849

CVE-2026-64849 is a Server-Side Request Forgery (SSRF) vulnerability in MLflow, added to the CISA Known Exploited Vulnerabilities (KEV) catalogue on 19 August 2026, signalling confirmed in-the-wild exploitation of the machine-learning orchestration platform.

Attribute Detail
CVE CVE-2026-64849
Type Server-Side Request Forgery (SSRF)
Product MLflow (widely used for ML workflows)
KEV added 2026-08-19 (federal 14-day patch cadence)
Source CISA โ€” Tier 1/4

The add continues the federal 14-day patch-file cadence following the larger four-vulnerability batch earlier that week, and puts internet-exposed MLflow deployments on notice.

Source