CISA warned that hackers are actively exploiting a critical flaw in MLflow, an open-source AI platform used to build and monitor machine-learning and agent systems. The bug, CVE-2026-64849, is a DNS-rebinding server-side request forgery flaw in MLflow webhook delivery, patched in MLflow 3.15.0. On default unauthenticated tracking servers, attackers can use the webhook test endpoint to reach internal services, scan hosts, and read cloud metadata responses including AWS IAM credentials.
Why it matters: Organizations running internet-exposed MLflow servers should treat this as urgent and patch to 3.15.0 or later immediately, especially if instances are reachable without authentication. The flaw can expose internal systems and cloud credentials without the attacker needing an account.
Ionut Arghire
2026.08.20
98% relevant
This article updates the same MLflow CVE-2026-64849 event with specific exploitation details: attackers are using the unauthenticated SSRF to query cloud metadata services and steal cloud credentials and secrets from exposed MLflow instances, and WatchTowr says exploitation began within hours of CVE assignment. It also reiterates affected versions before 3.15.0.
Sergiu Gatlan
2026.08.20
100% relevant
This article establishes a new tracked story because it centers on CISA confirming active exploitation of CVE-2026-64849 in MLflow and adding it to KEV, with no existing tracked story for this specific vulnerability.
← Back to all stories