CVE-2026-64849: MLflow Server-Side Request Forgery Vulnerability

Summary

MLflow has a server-side request forgery (SSRF) vulnerability that could allow attackers to access internal or cloud metadata services. Affected users are instructed to apply vendor mitigations and follow CISA's guidance on prioritizing security updates.

IFF Assessment

FOE

The identified vulnerability allows attackers to access sensitive internal or cloud metadata, posing a significant risk to defenders.

Severity

9.3 Critical

CISA KEV: Listed as actively exploited. Federal patch due: September 02, 2026. Known ransomware use: Unknown.

Defender Context

This SSRF vulnerability in MLflow presents a critical risk, as it can be exploited to exfiltrate sensitive data from cloud metadata services or reach internal systems. Defenders should prioritize applying vendor-provided patches or implementing workarounds immediately, especially for internet-facing instances of MLflow.

Read Full Story →