U.S. CISA adds an MLflow flaw to its Known Exploited Vulnerabilities catalog
ID: c4b7b3e1-2a2f-5106-a85e-1b3bb1b38844
STIX ID: report--c4b7b3e1-2a2f-5106-a85e-1b3bb1b38844
Feed Name: Security Affairs
Threat Score
CISA added MLflow vulnerability CVE-2026-64849 (unauthenticated SSRF, CVSS 9.3) to its Known Exploited Vulnerabilities catalog; attackers are actively exploiting the flaw to reach cloud metadata endpoints and steal temporary credentials, and widespread scanning for exposed MLflow instances was observed soon after the CVE was assigned.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
