Thehackernews
Active Exploitation of MLflow SSRF Vulnerability CVE-2026-64849
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A critical unauthenticated server-side request forgery (SSRF) vulnerability in MLflow, tracked as CVE-2026-64849, is being actively exploited within hours of its disclosure on August 17, 2026. This flaw affects MLflow versions prior to 3.15.0 and can expose sensitive data, including cloud credentials and internal services, to remote attackers. The vulnerability was confirmed by watchTowr, indicating a significant risk for organizations using affected versions. Attackers can leverage this flaw to gain unauthorized access to sensitive information, raising concerns about data breaches. Security teams are urged to assess their systems and apply necessary patches immediately to mitigate risks.
Key Points: • CVE-2026-64849 is a critical SSRF vulnerability in MLflow affecting versions before 3.15.0. • The flaw allows attackers to expose cloud credentials and internal services. • Active exploitation of this vulnerability was reported within hours of its public disclosure.