The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical server-side request forgery (SSRF) vulnerability in the open-source MLflow framework to its Known Exploited Vulnerabilities (KEV) catalog. Tracked as CVE-2026-64849 and assigned a CVSS severity score of 9.3, the flaw allows unauthenticated attackers to manipulate tracking servers into issuing arbitrary outbound HTTP requests. Under Binding Operational Directive 22-01, the KEV listing triggers a mandatory 14-day remediation deadline for federal civilian agencies, establishing a compliance baseline that industry analysts expect private sector and critical infrastructure operators to follow.

The vulnerability targets MLflow’s tracking server, a core component responsible for logging model parameters, metrics, and artifacts throughout the machine learning lifecycle. Security researchers have confirmed active exploitation in production environments, with threat actors leveraging the SSRF flaw to harvest cloud instance metadata, establish lateral movement pathways, and potentially execute arbitrary code within containerized AI workloads. Because MLflow deployments are routinely exposed to internal or external networks to facilitate collaborative research and development, the expanded attack surface presents a high-value target for sophisticated adversaries.

In response, security teams should implement a two-track mitigation strategy. Organizations must immediately inventory all MLflow tracking servers and deploy the official vendor patch within the mandated 14-day window. Because enterprise patching cycles often lag behind federal directives, administrators should deploy compensating network controls concurrently. Strict egress filtering, workload segmentation, and continuous monitoring of outbound traffic are essential to block active exploitation attempts and detect any prior compromise.

The KEV designation underscores a structural shift in enterprise risk management: AI and machine learning infrastructure can no longer be treated as isolated experimental environments. Historically deprioritized in traditional IT security programs, ML toolchains now require formal integration into standard vulnerability management and risk frameworks. As organizations accelerate their adoption of open-source AI platforms, maintaining rigorous security hygiene—including automated asset tracking, version verification, and standardized patching cadences—will be critical to protecting core operational pipelines.


美國網絡安全及基礎設施安全局(CISA)已將開源 MLflow 框架中的一項關鍵伺服器端請求偽造(SSRF)漏洞,納入其已知遭利用漏洞(KEV)目錄。該漏洞編號為 CVE-2026-64849,CVSS 嚴重性評分為 9.3,允許未經認證的攻擊者操控 tracking server 發出任意的對外 HTTP 請求。根據 Binding Operational Directive 22-01,此 KEV 列入名單觸發了聯邦民事機構必須在 14 日內完成修補的強制期限,並確立了合規基準,業界分析師預期私營機構及關鍵基礎設施營運商亦會跟從。

該漏洞針對 MLflow 的 tracking server,此為機器學習週期中負責記錄模型參數、指標及 artifacts 的核心組件。安全研究人員已確認該漏洞在生產環境中遭主動利用,威脅行為者正利用此 SSRF 缺陷擷取雲端實例 metadata、建立橫向移動路徑,並可能在 containerized AI workloads 中執行任意程式碼。由於 MLflow 部署通常會暴露於內部或外部網絡以促進協作研發,擴大的攻擊面已成為進階攻擊者的高價值目標。

對此,安全團隊應實施雙軌緩解策略。機構必須立即盤點所有 MLflow tracking server,並在規定的 14 日期限內部署官方供應商 patch。由於企業的 patching cycles 往往落後於聯邦指令,管理員應同步部署補償性網絡控制措施。嚴格的 egress filtering、工作負載分段,以及持續監控對外流量,對於阻擋主動利用嘗試及偵測任何先前遭入侵情況至關重要。

KEV 的指定突顯了企業風險管理的結構性轉變:AI 與機器學習基礎設施已不能再被視為孤立的實驗環境。機器學習工具鏈在傳統 IT 安全計劃中歷來被置於次要地位,但現在必須正式納入標準的漏洞管理與風險框架。隨著機構加速採用開源 AI 平台,維持嚴謹的安全防護常規——包括自動化資產追蹤、版本驗證及標準化的 patching cadences——將對保護核心營運 pipeline 至關重要。

新聞來源 / Original News Source