What is CVE-2026-64849?
CVE-2026-64849 is a high-severity (CVSS 9.3) MLflow vulnerability added to CISA's Known Exploited Vulnerabilities catalog. It requires immediate patching on affected systems due to active exploitation.
Azərbaycanca: CVE-2026-64849 yüksək kritikliyə malik (CVSS 9.3) MLflow boşluğudur. CISA bu zəifliyi aktiv istismar olunan boşluqlar kataloquna əlavə edib. Təsirlənən sistemlərdə təcili yamaq tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: shared vendor: Progress
FAQ2
What is the severity level of CVE-2026-64849 and is there confirmed active exploitation?
This vulnerability is high-severity (CVSS 9.3) and its active exploitation has been confirmed by its addition to the CISA Known Exploited Vulnerabilities catalog.
What immediate action is recommended for MLflow systems affected by CVE-2026-64849?
Due to active exploitation, it is recommended to apply immediate patching on affected systems.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.