MLflow lands on the CISA KEV list after an SSRF that reads your cloud metadata
On August 19, 2026, CISA added CVE-2026-64849, an unauthenticated SSRF in MLflow, to its Known Exploited Vulnerabilities catalog. Any exposed MLflow tracking server should move to 3.15.0 and drop unused webhooks before the September 2, 2026 deadline.