Skip to content

Critical MLflow SSRF Flaw Exploited in the Wild

Gbhackers •Divya • August 18, 2026

A critical unauthenticated server-side request forgery (SSRF) vulnerability in MLflow, tracked as CVE-2026-64849, is being actively exploited within hours of its disclosure, according to watchTowr. This flaw affects MLflow versions before 3.15.0 and can expose cloud credentials, internal services, and other sensitive data to remote attackers. MLflow SSRF Flaw The vulnerability exists in MLflow’s model-registry […]

Extracted Entities