netVigilance Vulnerability intelligence since 2004

MLflow

1 MLflow vulnerability with confirmed exploitation in the wild, as published by CISA; 1 past the federal remediation deadline. This is a static slice of the catalog — open the full catalog for search and filters.

Known exploited vulnerabilities for MLflow
Vulnerability Status
overdue 8d2026-09-02 CVE-2026-64849 MLflow / MLflow MLflow Server-Side Request Forgery Vulnerability 2026-08-19 9.3 past due