VDB

CVE-2026-64849

CVE-2026-64849 PUBLISHED KEV

As of August 17, 2026, MLflow is affected by vulnerabilities in the following product: MLflow Prior to 3.15.0 On August 19, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-64849 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.

EPSS 16.41% · 96.7th percentile

Risk Scores

EPSS Score
16.41%
96.7th percentile

Affected Products

VendorProductVersions
PriorPrior to 3.15.0

Timeline

  • Apr 5, 2023 CrowdSec Sighting
  • Jun 28, 2025 CrowdSec Sighting
  • Jul 19, 2026 CrowdSec Sighting
  • Aug 17, 2026 CVE Published
  • Aug 18, 2026 VulnCheck KEV Exploitation
  • Aug 19, 2026 CISA KEV Added
  • Aug 19, 2026 VulnCheck KEV Exploitation
  • Aug 21, 2026 Security Advisory
  • Aug 22, 2026 Coalition ESS Score
  • Aug 24, 2026 EPSS Score
  • Aug 27, 2026 VulnCheck KEV Exploitation
  • Sep 3, 2026 VulnCheck KEV Exploitation
Open in Interactive Console →
$ Console Community · 100/wk Open console ›