Skip to content
Security Alerts

CVE-2026-64849: Actively exploited SSRF in MLflow (CISA KEV)

MLflow's unauthenticated webhook test endpoint validates only the original URL and then follows redirects, opening an SSRF...

Summary

ParameterValue
CVE IDCVE-2026-64849
Alert SourceCISA KEV - Active Exploitation
CVE Publication Year2026
Date Published2026-08-19
VendorMLflow
ProductMLflow
CVSS Score9.3 (critical)
EPSS Score1.1% (percentile: 63%)
CISA KEVYes - confirmed active exploitation
RansomwareNot confirmed
Remediation Deadline2026-09-02

Vulnerability Description

MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body.

Required Actions

This vulnerability is listed in CISA KEV — exploitation is confirmed, not hypothetical.

  1. Update MLflow to 3.15.0 or later. That is the only complete fix.
  2. Until you can update, cut off network access to the MLflow server from outside trusted segments. The endpoint is unauthenticated, so any exposure is an open door.
  3. Understand why SSRF matters here: MLflow servers usually sit on the same network as training data, artifact stores and cloud credentials. A request issued “from the inside” reaches what an external attacker cannot — including cloud instance metadata services.
  4. Run a compromise assessment, not just an update. A KEV listing means someone is already exploiting this. Check webhook endpoint access logs and unusual outbound requests from the MLflow host.
  5. Inventory your MLflow instances — they are often spun up by data science teams outside standard IT process and may not appear in the systems register.

Who Is Affected?

Organizations using MLflow for machine learning lifecycle management. Instances are often spun up by analytics teams outside standard IT process — the most common reason such a vulnerability goes unnoticed despite a CISA KEV listing.

Sources


Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.

Learn More

Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist