watchTowr[verified]@watchtowrcyberActive Exploitation
CVE-2026-64849 is an unauthenticated SSRF vulnerability in MLflow that is already being actively exploited; all versions prior to 3.15.0 need immediate patching and monitoring.
ThreatWire[verified]@ThreatWire_PoC
A publicly available PoC for CVE‑2026‑64849 has been released, evidence of active exploitation exists, and the vulnerability is a high‑severity SSRF.
kokumօtօ[verified]@__kokumotoActive Exploitation
CISA reports CVE‑2026‑64849, an SSRF flaw in MLflow, as a known exploited vulnerability with a remediation deadline, indicating active exploitation but no PoC or exploit code was shared.
Aikido Community Japan[verified]@AikidoCommJPActive Exploitation
The post highlights that CVE‑2026‑64849 in MLflow is already being exploited in the wild, urging immediate upgrades and credential rotations to protect underlying cloud environments.
Misbar | مسبار[verified]@MisbarSecActive Exploitation
The post announces that CVE-2026-64849, a critical SSRF flaw in MLflow, is currently being exploited in the wild (as per CISA’s catalog) and recommends immediate patching and network monitoring.
Cyber Edition[verified]@CyberEditionActive Exploitation
An unauthenticated SSRF flaw in MLflow (CVE-2026-64849) is actively being exploited, potentially exposing internal services; users are urged to upgrade to 3.15.0+ to mitigate the risk.
Machina Record[verified]@MachinaRecordPatch
The article summarizes recent vulnerability disclosures, many with confirmed patches and active exploitation, highlighting the importance of timely remediation.
piyokango[verified]@piyokangoActive Exploitation
The post confirms that CVE‑2026‑64849 is actively exploited, with PoC evidence, and highlights available patch information.