CVE-2026-64849
- CVSS
- —
- EPSS
- 0.098 (95.4th percentile)
- CISA KEV
- Added 2026-08-19, due 2026-09-02
- Exploitation
- No report
- Public exploits
- 4 repositories
- State
- Unknown
Coverage
Actively exploitedCritical 70CISA advisories & alerts
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-64849 MLflow Server-Side Request Forgery Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses…
What we observed
- poc publishedpoc-in-github
- poc publishedpoc-in-github
- poc publishedpoc-in-github
- poc publishedpoc-in-github
- kev addedcisa-kev