Find notable cyber news and cases, enriched with sources, timelines, and signals.

MLflow unauthenticated SSRF flaw (CVE-2026-64849)

Vulnerability
First reported
Last updated
Happening score
H score 49
1 unique sources, 1 articles

Summary

Hide ▲

CVE-2026-64849 in MLflow is being actively exploited against exposed Tracking Server deployments, creating immediate risk of cloud credential and secret theft. Attackers are using the unauthenticated SSRF flaw to reach cloud metadata services and extract sensitive data from internal endpoints. Scanning for exposed MLflow instances began within hours of assignment on August 17, 2026, showing rapid abuse of internet-facing systems. Organizations running versions < 3.15.0 should patch affected systems and check for signs of compromise.

Related Happenings

MLflow and FUXA active exploitation wave

Exploitation Wave
H score51 First: 18.08.2026 20:44 Last: 18.08.2026 20:44 Sources 1

How related: Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operational technology (OT) and industrial automation, are witnessing malicious scanning and exploitation efforts.

About this happening: Active scanning and exploitation of MLflow and FUXA vulnerabilities is putting exposed systems at risk of cloud credential theft and remote code execution. CVE-2...

CISA orders federal mitigation of CVE-2026-16812

Public Sector Action
H score36 First: 28.07.2026 01:49 Last: 28.07.2026 01:49 Sources 1

About this happening: CISA added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog and ordered U.S. federal civilian executive branch agencies to mitigate it by July 30, 2...

Langflow CVE-2026-33017 exploitation wave

Exploitation Wave
H score50 First: 20.03.2026 12:20 Last: 20.03.2026 12:20 Sources 1

About this happening: CVE-2026-33017 in Langflow was disclosed on March 17, 2026 as an unauthenticated RCE with CVSS 9.3, allowing arbitrary Python execution from a single HTTP requ...

Timeline

  1. 18.08.2026 20:44 2 articles · 3h ago

    Attackers exploit CVE-2026-64849 in exposed MLflow Tracking Servers

    Exploitation Observed

    Within hours of the August 17, 2026 CVE assignment, attackers were scanning exposed MLflow instances and exploiting CVE-2026-64849 to proxy requests through model-registry webhooks, reach internal cloud metadata endpoints, and exfiltrate cloud credentials and secrets.

    Show sources
  2. 18.08.2026 20:44 1 articles · 3h ago

    Security researchers warn of active CVE-2026-64849 exploitation in MLflow

    Initial Disclosure

    Security researchers said attackers were exploiting CVE-2026-64849 against MLflow Tracking Server deployments to reach cloud metadata services and extract sensitive data, and urged organizations running MLflow to patch exposed systems, review audit logs, and check whether credentials had been exposed.

    Show sources