CISA Flags Actively Exploited MLflow Vulnerability — Act Now
The US Cybersecurity and Infrastructure Security Agency (CISA) has added a new vulnerability, CVE-2026-64849, to its Known Exploited Vulnerabilities (KEV) Catalog. This flaw affects MLflow Server and is a type known as Server-Side Request Forgery (SSRF), a vulnerability class that attackers frequently exploit to gain unauthorised access to systems and internal networks.
CISA confirmed there is evidence of active exploitation of this vulnerability, meaning cybercriminals are already using it in real attacks. While CISA's related directive, BOD 26-04, formally applies only to US federal agencies, the agency strongly encourages all organisations — including small and medium businesses worldwide — to adopt the same risk-based approach: prioritise patching vulnerabilities that are known to be actively exploited, especially on systems exposed to the internet.
For Australian small businesses using MLflow or similar machine learning infrastructure tools, this serves as a reminder that AI and data science platforms are increasingly becoming attack targets, not just traditional business software. Even if you don't directly use MLflow, this highlights the broader importance of keeping all software components patched and monitoring vendor security advisories.