# Researchers report active abuse of critical MLflow SSRF flaw

_Published Tuesday, August 18, 2026 at 3:08 PM EDT · Security · Developing · Tier 1 — Major_

![Researchers report active abuse of critical MLflow SSRF flaw — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiOzcJe940Ayk9JrnE-tmotZ-mEHZiA5Jc0A8Sw9IZIfYEnH61X8whAW6jJZTnzLIQYA37foce9X_fshoAVwjLyBKrjvHbkuhhtwZ2Mewxtf1Syn9FBOvZBqwcMWXOCKFNnASyrCOQ9XTF6f174Aa4O55O7tbU6evYcrrV0H_psoYYq3uQQ_GvZqsu0e0ik/s1700-e365/mlflow.jpg)

Independent researchers watchTowr and VulnCheck reported active scanning and exploitation of an unauthenticated MLflow server-side request forgery flaw, CVE-2026-64849. The vulnerability affects MLflow versions earlier than 3.15.0 and can let an attacker who reaches the Tracking Server send requests to internal cloud metadata endpoints. watchTowr said honeypot telemetry indicated attempts to extract cloud credentials and secrets beginning within hours of the CVE's August 17 assignment.

## Sources

- [The Hacker News](https://thehackernews.com/2026/08/attackers-exploit-mlflow-ssrf-flaw-to.html)

---
Canonical: https://techandbusiness.org/newswire/syRWgJuoVuE1vttdQsAtKI
Published: 2026-08-18T19:08:01.688Z
Story chronology: 2026-08-18T17:44:05.000Z
Retrieved: 2026-10-03T04:44:21.608Z
Publisher: Tech & Business (techandbusiness.org)
