Frequency
4
occurrences
First Seen
August 18, 2026
Last Seen
September 28, 2026
Exploited in Wild
—
Ransomware Use
—
Public Exploits
—
Attack Vector
—
Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
A critical unauthenticated server-side request forgery (SSRF) vulnerability in MLflow, tracked as CVE-2026-64849, is being actively exploited within hours of its disclosure on August 17, 2026. This flaw affects MLflow versions prior to 3.15.0 and can expose sensitive data, including cloud credential...
A critical SSRF vulnerability (CVE-2026-64849) in MLflow, the world's most downloaded ML platform, allows unauthorized access to metadata services on AWS, Azure, and GCP. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its catalog of actively exploited th...
Public Exploits
Checking GitHub for proof-of-concept code…