Skip to content

Critical MLflow SSRF Vulnerability Exploited by Hackers in the Wild

Cybersecuritynews •Guru Baran • August 18, 2026

Threat actors are actively exploiting a critical, unauthenticated server-side request forgery (SSRF) vulnerability in MLflow, the popular open-source platform widely used by data engineering and machine learning teams to track experiments, package code, and deploy models. Tracked as CVE-2026-64849 with a critical CVSS 3.1 score of 9.3, the flaw impacts all MLflow versions prior to […]

Extracted Entities