← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 20, 2026 · 08:55via Security Affairs

U.S. CISA adds an MLflow flaw to its Known Exploited Vulnerabilities catalog

Brief

U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds an MLflow vulnerability to its Known Exploited Vulnerabilities catalog.

The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added a Progress LoadMaster vulnerability, tracked as CVE-2026-64849 (CVSS score of 9. 3), to its Known Exploited Vulnerabilities (KEV) catalog .

CVE-2026-64849 is a critical server-side request forgery (SSRF) vulnerability in MLflow, a platform for managing machine-learning workflows. The issue affects MLflow versions before 3.

  • 0 and a remote attacker can exploit the issue without authentication.

The vulnerability allows attackers to make requests from an exposed MLflow server to internal services, including cloud metadata endpoints, potentially exposing temporary cloud credentials.

Read more on Security Affairs