Affected organizations should apply updates from the MLflow vendor to mitigate the SSRF vulnerability. CISA encourages prioritization of rapid remediation. Federal Civilian Executive Branch agencies must follow Binding Operational Directive 26-04, which requires rapid remediation of KEV Catalog vulnerabilities on publicly exposed assets and establishes expectations for checking whether threat actors compromised the system before the patch was applied. Organizations should monitor CISA advisories and MLflow vendor guidance for specific patch information and version details.
Quick answers
What is CVE-2026-64849?
Affected organizations should apply updates from the MLflow vendor to mitigate the SSRF vulnerability. CISA encourages prioritization of rapid remediation. Federal Civilian Executive Branch agencies must follow Binding Operational Directive 26-04, which requires rapid remediation of KEV Catalog vulnerabilities on publicly exposed assets and establishes expectations for checking whether threat actors compromised the system before the patch was applied. Organizations should monitor CISA advisories and MLflow vendor guidance for specific patch information and version details.
How severe is CVE-2026-64849?
high
Is CVE-2026-64849 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-64849 be mitigated?
Affected organizations should apply updates from the MLflow vendor to mitigate the SSRF vulnerability. CISA encourages prioritization of rapid remediation. Federal Civilian Executive Branch agencies must follow Binding Operational Directive 26-04, which requires rapid remediation of KEV Catalog vulnerabilities on publicly exposed assets and establishes expectations for checking whether threat actors compromised the system before the patch was applied. Organizations should monitor CISA advisories and MLflow vendor guidance for specific patch information and version details.
CVSS
—
Vendor
—
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
MLflow
Mitigation
Affected organizations should apply updates from the MLflow vendor to mitigate the SSRF vulnerability. CISA encourages prioritization of rapid remediation. Federal Civilian Executive Branch agencies must follow Binding Operational Directive 26-04, which requires rapid remediation of KEV Catalog vulnerabilities on publicly exposed assets and establishes expectations for checking whether threat actors compromised the system before the patch was applied. Organizations should monitor CISA advisories and MLflow vendor guidance for specific patch information and version details.
The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-64849, a Server-Side Request Forgery (SSRF) vulnerability in MLflow, to its Known Exploited Vulnerabilities (KEV) Catalog. The addition is based on evidence of active exploitation. CISA's Binding Operational Directive 26-04 requires Federal Civilian Executive Branch agencies to prioritize rapid remediation of this vulnerability on publicly exposed assets that grant total control post-exploitation, and to check for pre-compromise before patching.