# Researchers report active abuse of critical MLflow SSRF flaw

_Tuesday, August 18, 2026 at 1:44 PM EDT · Security · Developing · Tier 1 — Major_

![Researchers report active abuse of critical MLflow SSRF flaw — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiOzcJe940Ayk9JrnE-tmotZ-mEHZiA5Jc0A8Sw9IZIfYEnH61X8whAW6jJZTnzLIQYA37foce9X_fshoAVwjLyBKrjvHbkuhhtwZ2Mewxtf1Syn9FBOvZBqwcMWXOCKFNnASyrCOQ9XTF6f174Aa4O55O7tbU6evYcrrV0H_psoYYq3uQQ_GvZqsu0e0ik/s1700-e365/mlflow.jpg)

Independent researchers watchTowr and VulnCheck reported active scanning and exploitation of an unauthenticated MLflow server-side request forgery flaw, CVE-2026-64849. The vulnerability affects MLflow versions earlier than 3.15.0 and can let an attacker who reaches the Tracking Server send requests to internal cloud metadata endpoints. watchTowr said honeypot telemetry indicated attempts to extract cloud credentials and secrets beginning within hours of the CVE's August 17 assignment.

## Sources

- [The Hacker News](https://thehackernews.com/2026/08/attackers-exploit-mlflow-ssrf-flaw-to.html)

---
Canonical: https://techandbusiness.org/newswire/syRWgJuoVuE1vttdQsAtKI
Retrieved: 2026-08-18T21:09:29.539Z
Publisher: Tech & Business (techandbusiness.org)
