Ciberseguridadlatam
Critical SSRF Vulnerability in MLflow Actively Exploited, CISA Issues Warning
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Article Content
A critical SSRF vulnerability (CVE-2026-64849) in MLflow, the world's most downloaded ML platform, allows unauthorized access to metadata services on AWS, Azure, and GCP. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its catalog of actively exploited threats on August 19, 2026. The flaw, which lacks authentication, poses a significant risk to cloud environments. As of August 21, 2026, the vulnerability is under active exploitation, with confirmed incidents of credential theft reported. Organizations using MLflow are advised to take immediate action to mitigate this risk.
Key Points: • CVE-2026-64849 is a critical SSRF vulnerability in MLflow affecting major cloud platforms. • CISA added this vulnerability to its active threats list on August 19, 2026. • Credential theft incidents have been confirmed due to this vulnerability.