CISA warns of hackers exploiting critical MLflow vulnerability
Reported exploitedMLflowOur summary
CISA has identified active real-world attacks targeting a critical server-side request forgery flaw in MLflow, tracked as CVE-2026-64849. This unauthenticated DNS-rebinding bypass affects the outbound webhook delivery mechanism and enables attackers to steal cloud credentials, such as AWS IAM keys, from internal services. The vulnerability is resolved in MLflow 3.15.0, and federal agencies have been ordered to apply the patch within two weeks under Binding Operational Directive 26-04.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.