
🚨 If you're running MLflow, stop and read this. CVE-2026-64849 is a critical unauthenticated SSRF discovered in the default MLflow Tracking server. It lets attackers reach internal services and potentially steal sensitive data without requiring a login, and it's already being exploited in the wild. We recommend upgrading to version 3.15.0 as it also fixes two additional flaws affecting MLflow, CVE-2026-69148 and CVE-2026-69146. More details: https://devhub.checkmarx.com/cve-details/CVE-2026-64849/
Post summary
CVE-2026‑64849 is a critical unauthenticated SSRF in MLflow, actively exploited in the wild; updating to 3.15.0 resolves the issue.

