CISA warns of hackers exploiting critical MLflow vulnerability

CISA warns of hackers exploiting critical MLflow vulnerability
CISA warned federal agencies that attackers are exploiting CVE-2026-64849, a critical MLflow DNS-rebinding SSRF bypass that can expose internal services and cloud metadata on unpatched systems. The flaw in MLflow’s webhook delivery can let unauthenticated attackers steal AWS IAM credentials, prompting CISA to add it to its exploited-in-the-wild catalog and order rapid patching. #CVE-2026-64849 #MLflow #CISA #AWSIMDS #IAM

Keypoints

  • CISA says CVE-2026-64849 is being actively exploited.
  • The flaw affects MLflow’s outbound webhook delivery.
  • Unauthenticated attackers can trigger SSRF to reach internal and cloud-metadata endpoints.
  • Exploitation can expose AWS IAM credentials and other internal services.
  • CISA ordered U.S. federal agencies to patch MLflow within two weeks.

Read More: https://www.bleepingcomputer.com/news/security/cisa-warns-of-hackers-exploiting-critical-mlflow-vulnerability/