Vulnerabilities & PatchesEmerging1 src
Hackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets
Threat actors are actively targeting cloud-hosted MLflow deployments following the disclosure of CVE-2026-64849, an unauthenticated server-side request forgery (SSRF) flaw affecting all versions of the machine learning platform prior to 3. 15. 0.
watchTowr Intel reported that its Attacker Eye global honeypot network detected exploitation attempts within hours of the CVE being assigned.
The rapid activity suggests attackers are immediately scanning for exposed MLflow instances and attempting to abuse the vulnerability to access sensitive cloud resources, including credentials, API tokens, and application secrets.
Hackers Exploit MLflow SSRF Flaw
SSRF vulnerabilities allow an attacker to coerce a vulnerable server into issuing requests on their behalf.