PulseAugur
EN
LIVE 05:01:16

Critical MLflow SSRF vulnerability (CVE-2026-64849) actively exploited

A critical server-side request forgery (SSRF) vulnerability, CVE-2026-64849, has been discovered in MLflow, a platform for managing the machine learning lifecycle. The flaw, which has a CVSS score of 9.3 and requires no authentication, allows attackers to exfiltrate cloud credentials by accessing internal resources and metadata endpoints. Exploitation in the wild has been confirmed, with active scanning and proof-of-concept exploits already available, and the vulnerability has been added to the CISA Known Exploited Vulnerabilities catalog. AI

IMPACT This critical vulnerability in MLflow could lead to widespread credential theft and system compromise for AI/ML operations.

RANK_REASON The cluster reports on a specific vulnerability and its exploitation in a widely used machine learning platform.

Read on Mastodon — mastodon.social →

AI-generated summary · Google Gemini · from 2 sources. How we write summaries →

Critical MLflow SSRF vulnerability (CVE-2026-64849) actively exploited

How we ranked this

Signal score
0 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
The cluster reports on a specific vulnerability and its exploitation in a widely used machine learning platform.
Source corroboration
2 independent sources
Multiple independent publishers reporting the same story raises confidence that it's real and newsworthy.
Topics
infra, other
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
50 days old
Aged out of breaking-news scoring windows; ranking reflects the durable signal from the full source set.

Full methodology in our editorial standards.

COVERAGE [2]

  1. Mastodon — mastodon.social TIER_1 English(EN) · stemshop ·

    🚨 CVE-2026-64849 — Critical MLflow SSRF CVSS 9.3 • No authentication required • Public PoC available • Nuclei template released • Active exploitation confirmed

    🚨 CVE-2026-64849 — Critical MLflow SSRF CVSS 9.3 • No authentication required • Public PoC available • Nuclei template released • Active exploitation confirmed • Added to CISA KEV. The flaw can expose internal resources and potentially leak AWS/Azure/GCP cloud credentials. https:…

  2. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    🤖 CVE-2026-64849 (CVSS 9.3): unauthenticated SSRF in MLflow (< 3.15.0) exploited in the wild to exfiltrate cloud credentials via metadata endpoints. Scans began

    🤖 CVE-2026-64849 (CVSS 9.3): unauthenticated SSRF in MLflow (< 3.15.0) exploited in the wild to exfiltrate cloud credentials via metadata endpoints. Scans began hours after the Aug 17 disclosure; bypasses prior fixes via redirect handling. Also CVE-2026-25895 (CVSS 9.5): path tra…