VDB
CVE-2026-64849
CVE-2026-64849
PUBLISHED
KEV
As of August 17, 2026, MLflow is affected by vulnerabilities in the following product: MLflow Prior to 3.15.0 On August 19, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-64849 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
EPSS 16.41% · 96.7th percentile
Risk Scores
EPSS Score
16.41%
96.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Prior | Prior to 3.15.0 |
Timeline
- Apr 5, 2023 CrowdSec Sighting
- Jun 28, 2025 CrowdSec Sighting
- Jul 19, 2026 CrowdSec Sighting
- Aug 17, 2026 CVE Published
- Aug 18, 2026 VulnCheck KEV Exploitation
- Aug 19, 2026 CISA KEV Added
- Aug 19, 2026 VulnCheck KEV Exploitation
- Aug 21, 2026 Security Advisory
- Aug 22, 2026 Coalition ESS Score
- Aug 24, 2026 EPSS Score
- Aug 27, 2026 VulnCheck KEV Exploitation
- Sep 3, 2026 VulnCheck KEV Exploitation
References
- https://cyber.gc.ca/en/alerts-advisories/mlflow-security-advisory-av26-832 advisory
- https://github.com/mlflow/mlflow/releases/tag/v3.15.0 vendor
- https://github.com/mlflow/mlflow/security/advisories/GHSA-7gwp-5pfp-969j vendor
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-64849 advisory