securityaffairs.com 8/20/2026, 10:01:49 AM · external

SSRF bug in MLflow (CVE-2026-64849) exposes cloud secrets

SSRF bug in MLflow (CVE-2026-64849) exposes cloud secrets
Developing story vulnerability 4 articles tracked
MLflow SSRF flaw (CVE-2026-64849) exploited in the wild
CyberSIXT Evidence Panel
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Available

THE U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability (CVE-2026-64849) in MLflow, a platform for machine-learning workflows, to its Known Exploited Vulnerabilities catalog. This server-side request forgery (SSRF) vulnerability affects MLflow versions prior to 3.15.0 and can be exploited by a remote attacker without authentication, potentially exposing cloud metadata and credentials. Following its assignment on August 17, 2026, there have been active exploits and widespread scanning for affected MLflow instances.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline