Find notable cyber news and cases, enriched with sources, timelines, and signals.

MLflow unauthenticated SSRF flaw (CVE-2026-64849)

Vulnerability
First reported
Last updated
Happening score
H score 43
2 unique sources, 2 articles

Summary

Hide ▲

CVE-2026-64849 in MLflow is being actively exploited against exposed Tracking Server deployments, creating immediate risk of cloud credential and secret theft. Attackers are using the unauthenticated SSRF flaw to reach cloud metadata services and extract sensitive data from internal endpoints. Scanning for exposed MLflow instances began within hours of assignment on August 17, 2026, showing rapid abuse of internet-facing systems. Organizations running versions < 3.15.0 should patch affected systems and check for signs of compromise.

Related Happenings

MLflow and FUXA active exploitation wave

Exploitation Wave
H score46 First: 18.08.2026 20:44 Last: 18.08.2026 20:44 Sources 1

How related: The Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies that threat actors are now exploiting a critical MLflow vulnerability.

About this happening: Active scanning and exploitation of MLflow and FUXA vulnerabilities is putting exposed systems at risk of cloud credential theft and remote code execution. CVE-2...

Latest development: 20.08.2026 14:06

CISA added CVE-2026-64849 to its catalog of flaws exploited in the wild and ordered U.S. Federal Civilian Executive Branch agencies to secure MLflow instances within two weeks under Binding Operational Directive 26-04. The vulnerability is a critical DNS-rebinding server-side request forgery bypass in MLflow's outbound webhook delivery and can let an unauthenticated attacker reach internal services or cloud metadata endpoints on unpatched instances.

Knaithe / KnYuan AI-orchestrated exploitation campaign targeting internet-exposed infrastructure in Asia

Campaign
H score47 First: 31.07.2026 18:00 Last: 31.07.2026 18:00 Sources 1

About this happening: The knaithe / KnYuan campaign is an AI-orchestrated exploitation activity tied to Hermes Agent and DeepSeek, with Unit 42 describing autonomous enumeration and...

CISA orders federal mitigation of CVE-2026-16812

Public Sector Action
H score36 First: 28.07.2026 01:49 Last: 28.07.2026 01:49 Sources 1

About this happening: CISA added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog and ordered U.S. federal civilian executive branch agencies to mitigate it by July 30, 2...

CISA orders FCEB patching under BOD 26-04

Public Sector Action
H score36 First: 22.07.2026 14:43 Last: 22.07.2026 14:43 Sources 1

About this happening: CISA ordered U.S. Federal Civilian Executive Branch agencies to secure systems against CVE-2026-0770 in Langflow, setting a Friday deadline under BOD 26-04...

JDY botnet expanded reconnaissance and flaw-focused scanning activity

Malware Activity
H score27 First: 10.06.2026 18:00 Last: 10.06.2026 18:00 Sources 1

About this happening: The JDY botnet has expanded its reconnaissance and flaw-focused scanning, increasing the risk that exposed infrastructure will be rapidly identified and targeted. Research...

Timeline

  1. 18.08.2026 20:44 3 articles · 13d ago

    Attackers exploit CVE-2026-64849 in exposed MLflow Tracking Servers

    Exploitation Observed

    Within hours of the August 17, 2026 CVE assignment, attackers were scanning exposed MLflow instances and exploiting CVE-2026-64849 to proxy requests through model-registry webhooks, reach internal cloud metadata endpoints, and exfiltrate cloud credentials and secrets.

    Show sources
  2. 18.08.2026 20:44 1 articles · 13d ago

    Security researchers warn of active CVE-2026-64849 exploitation in MLflow

    Initial Disclosure

    Security researchers said attackers were exploiting CVE-2026-64849 against MLflow Tracking Server deployments to reach cloud metadata services and extract sensitive data, and urged organizations running MLflow to patch exposed systems, review audit logs, and check whether credentials had been exposed.

    Show sources