CISA says attackers are exploiting critical MLflow SSRF flaw CVE-2026-64849

CISA warned that hackers are actively exploiting a critical flaw in MLflow, an open-source AI platform used to build and monitor machine-learning and agent systems. The bug, CVE-2026-64849, is a DNS-rebinding server-side request forgery flaw in MLflow webhook delivery, patched in MLflow 3.15.0. On default unauthenticated tracking servers, attackers can use the webhook test endpoint to reach internal services, scan hosts, and read cloud metadata responses including AWS IAM credentials.
Why it matters: Organizations running internet-exposed MLflow servers should treat this as urgent and patch to 3.15.0 or later immediately, especially if instances are reachable without authentication. The flaw can expose internal systems and cloud credentials without the attacker needing an account.

Sources

MLflow Vulnerability Exploited for Cloud Credential Theft
Ionut Arghire 2026.08.20 98% relevant
This article updates the same MLflow CVE-2026-64849 event with specific exploitation details: attackers are using the unauthenticated SSRF to query cloud metadata services and steal cloud credentials and secrets from exposed MLflow instances, and WatchTowr says exploitation began within hours of CVE assignment. It also reiterates affected versions before 3.15.0.
CISA warns of hackers exploiting critical MLflow vulnerability
Sergiu Gatlan 2026.08.20 100% relevant
This article establishes a new tracked story because it centers on CISA confirming active exploitation of CVE-2026-64849 in MLflow and adding it to KEV, with no existing tracked story for this specific vulnerability.
← Back to all stories