logo

U.S. CISA adds an MLflow flaw to its Known Exploited Vulnerabilities catalog

ID: c4b7b3e1-2a2f-5106-a85e-1b3bb1b38844

STIX ID: report--c4b7b3e1-2a2f-5106-a85e-1b3bb1b38844

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-08-20

Date Updated: 2026-08-20

Author: Pierluigi Paganini

...
...

CISA added MLflow vulnerability CVE-2026-64849 (unauthenticated SSRF, CVSS 9.3) to its Known Exploited Vulnerabilities catalog; attackers are actively exploiting the flaw to reach cloud metadata endpoints and steal temporary credentials, and widespread scanning for exposed MLflow instances was observed soon after the CVE was assigned.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.