CVE Tools
Back to feed
Exploited in the wild MLflow cloud ai-ml

CISA warns of hackers exploiting critical MLflow vulnerability

BleepingComputer·By Sergiu Gatlan··2 min read
CVE Tools coverage

CISA has identified active real-world attacks targeting a critical server-side request forgery flaw in MLflow, tracked as CVE-2026-64849. This unauthenticated DNS-rebinding bypass affects the outbound webhook delivery mechanism and enables attackers to steal cloud credentials, such as AWS IAM keys, from internal services. The vulnerability is resolved in MLflow 3.15.0, and federal agencies have been ordered to apply the patch within two weeks under Binding Operational Directive 26-04.