CVE-2026-64849: MLflow Server-Side Request Forgery Vulnerability
Summary
MLflow has a server-side request forgery (SSRF) vulnerability that could allow attackers to access internal or cloud metadata services. Affected users are instructed to apply vendor mitigations and follow CISA's guidance on prioritizing security updates.
IFF Assessment
The identified vulnerability allows attackers to access sensitive internal or cloud metadata, posing a significant risk to defenders.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: September 02, 2026. Known ransomware use: Unknown.
Defender Context
This SSRF vulnerability in MLflow presents a critical risk, as it can be exploited to exfiltrate sensitive data from cloud metadata services or reach internal systems. Defenders should prioritize applying vendor-provided patches or implementing workarounds immediately, especially for internet-facing instances of MLflow.