CISA warns of hackers exploiting critical MLflow vulnerability
ID: 457ba782-9a99-531f-8833-db8c606258c3
STIX ID: report--457ba782-9a99-531f-8833-db8c606258c3
Feed Name: Bleeping Computer
Threat Score
CISA warned that a critical MLflow vulnerability (CVE-2026-64849) — an unauthenticated DNS-rebinding SSRF bypass in MLflow's webhook/test endpoint — is being exploited in the wild and can be used to access internal services and cloud metadata (e.g., AWS IMDS), enabling theft of cloud credentials; the flaw was patched in MLflow 3.15.0 and CISA added it to its KEV catalog and mandated patching for federal agencies under BOD 26-04.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
