Independent perspective. Actionable security.Know what matters · Reduce exposure

Vulnerability Assurance / Intelligence

MLflow SSRF Vulnerability (CVE-2026-64849) Added to CISA KEV

Source context: this article examines information published by the source on August 19, 2026. This site’s publication date is shown separately. Check the latest vendor guidance before acting.

What the vulnerability is

CVE-2026-64849 is a Server-Side Request Forgery (SSRF) vulnerability affecting MLflow. CISA has confirmed evidence of active exploitation, leading to its inclusion in the Known Exploited Vulnerabilities (KEV) Catalog on August 19, 2026.

Exposure and applicability

This vulnerability is applicable to organizations deploying MLflow. The risk is heightened for instances that are publicly exposed. Under Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch (FCEB) agencies are required to prioritize the remediation of KEV Catalog vulnerabilities on such assets, particularly those that could grant total control post-exploitation.

Remediation priorities

Based on the active exploitation status reported by CISA, our analysis suggests the following prioritization for vulnerability management teams:

  1. Publicly Exposed Assets: Immediate priority should be given to MLflow instances accessible from the internet, as these represent the most direct exposure path.
  2. Compromise Assessment: In alignment with BOD 26-04 expectations, defenders should evaluate whether systems were compromised prior to the application of patches or mitigations.
  3. Risk-Based Sequencing: Organizations not bound by FCEB directives are encouraged to adopt a similar risk-based approach, prioritizing this KEV entry over vulnerabilities without confirmed exploitation evidence.

How to validate remediation

To ensure exposure has been reduced, defenders should move beyond simple version checks. Validation should include:
* Configuration Audit: Verifying that the specific SSRF vector is neutralized through patching or compensating controls.
* Network Verification: Confirming whether MLflow instances are unnecessarily exposed to the public internet and applying restrictive access controls where possible.
* Integrity Checks: Performing a post-remediation review of system logs and configurations to ensure no unauthorized changes occurred during the window of exploitation.

Limits and open questions

While patching addresses the specific flaw identified in CVE-2026-64849, it does not eliminate the inherent risk of other SSRF vectors within the environment. Furthermore, while BOD 26-04 provides a framework for federal agencies to prioritize assets that grant total control post-exploitation, the specific technical impact and full extent of control granted by this particular CVE remain to be verified through independent technical analysis.

Source and editorial note

CISA Adds One Known Exploited Vulnerability to Catalog · Source date: August 19, 2026 · Retrieved August 31, 2026.

Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.

Request a Vulnerability Assessment

Turn security intelligence into action.

Discuss your exposure, priorities, and the evidence needed to validate the outcome.

Request a security assessment ↗

Turn security intelligence into action.

Understand exposure, prioritize the response, and define evidence for the outcome.

Request a Security Assessment