Security
Researchers report active abuse of critical MLflow SSRF flaw
Image: Primary Independent researchers watchTowr and VulnCheck reported active scanning and exploitation of an unauthenticated MLflow server-side request forgery flaw, CVE-2026-64849. The vulnerability affects MLflow versions earlier than 3.15.0 and can let an attacker who reaches the Tracking Server send requests to internal cloud metadata endpoints. watchTowr said honeypot telemetry indicated attempts to extract cloud credentials and secrets beginning within hours of the CVE's August 17 assignment.
Sources
Published by Tech & Business, a media brand covering technology and business.
This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire