logo

CISA warns of hackers exploiting critical MLflow vulnerability

ID: 457ba782-9a99-531f-8833-db8c606258c3

STIX ID: report--457ba782-9a99-531f-8833-db8c606258c3

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-08-20

Date Updated: 2026-08-20

Author: Sergiu Gatlan

...
...

CISA warned that a critical MLflow vulnerability (CVE-2026-64849) — an unauthenticated DNS-rebinding SSRF bypass in MLflow's webhook/test endpoint — is being exploited in the wild and can be used to access internal services and cloud metadata (e.g., AWS IMDS), enabling theft of cloud credentials; the flaw was patched in MLflow 3.15.0 and CISA added it to its KEV catalog and mandated patching for federal agencies under BOD 26-04.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.