CVE‑2026‑64849 MLflow Server‑Side Request Forgery Added to CISA KEV Catalog – Active Exploitation Threatens ML Ops Environments
What It Is – CISA has placed CVE‑2026‑64849, an SSRF flaw in the open‑source MLflow tracking server, into its Known Exploited Vulnerabilities (KEV) catalog after confirming active exploitation in the wild.
Exploitability – The vulnerability is being leveraged by threat actors to force the MLflow server to issue arbitrary HTTP requests on its behalf, potentially reaching internal services that are not otherwise exposed. No public proof‑of‑concept is required; exploitation is already observed.
Affected Products – MLflow (any self‑hosted deployment of the tracking server, versions prior to the vendor‑released fix).
Why It Matters for Compliance & Audit Readiness
- Control Mapping – SSRF gaps map to SOC 2 CC6.1 (System Operations) and CC7.1 (Change Management). Continuous evidence of remediation (patches, network segmentation) is required to demonstrate due diligence.
- Continuous Monitoring – The KEV designation signals a high‑risk, fast‑moving threat; auditors now expect organizations to have automated vulnerability‑management pipelines that surface such findings in real time.
- Audit Trail – Documenting the detection, risk assessment, and remediation of this CVE provides concrete audit artifacts that satisfy the “risk‑based remediation” expectations of Binding Operational Directive 26‑04 and emerging private‑sector SOC 2 expectations.
Recommended Actions
- Inventory all MLflow instances (cloud, on‑prem, containerized) and verify version.
- Apply the vendor‑issued patch or mitigate by restricting outbound network traffic from the MLflow host (e.g., egress firewall rules, allow‑list of destinations).
- Capture remediation evidence (patch tickets, configuration snapshots) in a centralized control‑mapping repository for SOC 2 audit readiness.
- Integrate the CVE into your vulnerability‑management toolchain and enable automated alerts for any future KEV additions.
Source: CISA Advisory – Known Exploited Vulnerabilities Catalog, 19 Aug 2026