A critical server-side request forgery (SSRF) vulnerability, CVE-2026-64849, has been discovered in MLflow, a platform for managing the machine learning lifecycle. The flaw, which has a CVSS score of 9.3 and requires no authentication, allows attackers to exfiltrate cloud credentials by accessing internal resources and metadata endpoints. Exploitation in the wild has been confirmed, with active scanning and proof-of-concept exploits already available, and the vulnerability has been added to the CISA Known Exploited Vulnerabilities catalog. AI
IMPACT This critical vulnerability in MLflow could lead to widespread credential theft and system compromise for AI/ML operations.
RANK_REASON The cluster reports on a specific vulnerability and its exploitation in a widely used machine learning platform.
Read on Mastodon — mastodon.social →
- CVE-2026-25895
- CVE-2026-64849
- FUXA SCADA/HMI
- metadata endpoints
- mlflow
- AWS
- Azure
- CISA KEV
- GCP
- nucleus
- server-side request forgery
AI-generated summary · Google Gemini · from 2 sources. How we write summaries →