
🚨 If you're running MLflow, stop and read this. CVE-2026-64849 is a critical unauthenticated SSRF discovered in the default MLflow Tracking server. It lets attackers reach internal services and potentially steal sensitive data without requiring a login, and it's already being exploited in the wild. We recommend upgrading to version 3.15.0 as it also fixes two additional flaws affecting MLflow, CVE-2026-69148 and CVE-2026-69146. More details: https://devhub.checkmarx.com/cve-details/CVE-2026-64849/
Post summary
The advisory warns of an actively exploited unauthenticated SSRF in MLflow and urges users to upgrade to version 3.15.0 to apply the patch.


