Skip to content
Active Exploitation of MLflow SSRF Vulnerability CVE-2026-64849

Active Exploitation of MLflow SSRF Vulnerability CVE-2026-64849

First seen 18 Aug 2026, 18:58 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •August 19, 2026 at 18:27 UTC
  • •CVE-2026-64849 is a critical SSRF vulnerability in MLflow affecting versions before 3.15.0.
  • •The flaw allows attackers to expose cloud credentials and internal services.
  • •Active exploitation of this vulnerability was reported within hours of its public disclosure.

A critical unauthenticated server-side request forgery (SSRF) vulnerability in MLflow, tracked as CVE-2026-64849, is being actively exploited within hours of its disclosure on August 17, 2026. This flaw affects MLflow versions prior to 3.15.0 and can expose sensitive data, including cloud credentials and internal services, to remote attackers. The vulnerability was confirmed by watchTowr, indicating a significant risk for organizations using affected versions. Attackers can leverage this flaw to gain unauthorized access to sensitive information, raising concerns about data breaches. Security teams are urged to assess their systems and apply necessary patches immediately to mitigate risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 45d ago How this analysis works

Timeline

2026-08-17
CVE-2026-64849 published
A critical SSRF vulnerability in MLflow was disclosed, affecting versions prior to 3.15.0.
Gbhackers
2026-08-18
Active exploitation reported
Researchers confirmed that the SSRF vulnerability is being actively exploited by attackers within hours of disclosure.
Gbhackers
2026-08-18
Threat assessment issued
Security teams are advised to assess their systems for the vulnerability and apply patches immediately.
Thehackernews

More articles in this cluster (8)

Following this threat?

Track MLflow and CVE-2026-64849 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed