PulseAugur
EN
LIVE 21:50:47

Critical MLflow SSRF Vulnerability (CVE-2026-64849) Exploited in the Wild

A critical vulnerability, CVE-2026-64849 with a CVSS score of 9.3, has been discovered in MLflow versions prior to 3.15.0. This unauthenticated Server-Side Request Forgery (SSRF) flaw allows attackers to exfiltrate cloud credentials by exploiting metadata endpoints. Exploitation in the wild was detected shortly after the vulnerability's disclosure on August 17th, with scans beginning hours later. The vulnerability can be bypassed through redirect handling, and a separate critical vulnerability, CVE-2026-25895 (CVSS 9.5), in FUXA SCADA/HMI allows for Remote Code Execution (RCE) via path traversal, also being actively scanned for. AI

IMPACT This vulnerability in MLflow, a tool often used in AI/ML workflows, could lead to compromised cloud credentials, impacting the security of AI development and deployment infrastructure.

RANK_REASON The cluster describes a vulnerability in a software tool (MLflow) and its exploitation, fitting the 'tool' bucket.

Read on Mastodon — mastodon.social →

AI-generated summary · Google Gemini · from 1 sources. How we write summaries →

Critical MLflow SSRF Vulnerability (CVE-2026-64849) Exploited in the Wild

COVERAGE [1]

  1. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    🤖 CVE-2026-64849 (CVSS 9.3): unauthenticated SSRF in MLflow (< 3.15.0) exploited in the wild to exfiltrate cloud credentials via metadata endpoints. Scans began

    🤖 CVE-2026-64849 (CVSS 9.3): unauthenticated SSRF in MLflow (< 3.15.0) exploited in the wild to exfiltrate cloud credentials via metadata endpoints. Scans began hours after the Aug 17 disclosure; bypasses prior fixes via redirect handling. Also CVE-2026-25895 (CVSS 9.5): path tra…