Skip to content

CVE-2026-64849

CVE

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
August 18, 2026
Last Seen
September 28, 2026
API
Exploited in Wild
—
Ransomware Use
—
Public Exploits
—
Attack Vector
—

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

A critical unauthenticated server-side request forgery (SSRF) vulnerability in MLflow, tracked as CVE-2026-64849, is being actively exploited within hours of its disclosure on August 17, 2026. This flaw affects MLflow versions prior to 3.15.0 and can expose sensitive data, including cloud credential...

A critical SSRF vulnerability (CVE-2026-64849) in MLflow, the world's most downloaded ML platform, allows unauthorized access to metadata services on AWS, Azure, and GCP. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its catalog of actively exploited th...

Public Exploits

Checking GitHub for proof-of-concept code…