CISA Adds One Known Exploited Vulnerability to Catalog

Summary

CISA has added a new Server-Side Request Forgery vulnerability in MLflow (CVE-2026-64849) to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. This action is in line with Binding Operational Directive (BOD) 26-04, which mandates federal agencies to prioritize the remediation of high-risk vulnerabilities listed in the KEV Catalog.

IFF Assessment

FOE

The addition of a known exploited vulnerability to CISA's KEV catalog signifies that malicious actors are actively leveraging this flaw, posing a direct threat to organizations and requiring immediate defensive action.

Severity

9.3 Critical

CISA KEV: Listed as actively exploited. Federal patch due: September 02, 2026. Known ransomware use: Unknown.

Defender Context

This update from CISA highlights the importance of actively monitoring and patching vulnerabilities listed in the KEV Catalog, as these are confirmed to be under active exploitation. Defenders should prioritize remediation efforts for CVE-2026-64849 and similar entries to mitigate known risks to their infrastructure.

Read Full Story →