CVE-2026-64849Active Exploitation(lfprojects / mlflow)

CRITICALCVSS 9.3 · CRITICALCISA KEV

Exploitation observed; activity peaked at 14 mentions and remains active

Immediate actions

  • Patch lfprojects mlflow systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Starting in 3.3.0 and prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while mlflow/webhooks/delivery.py follows redirects and re-resolves the hostname without pinning the validated address, allowing attackers to reach internal or cloud metadata services and receive response_status and response_body. This issue is fixed in version 3.15.0.

8.3/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-09-02. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weakness type (CWE)
CWE-918

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mlflow

Threat summary

  • Active exploitation appears in 46 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 64 mentions across 13 observed days

What's happening

  • Active exploitation reported across 46 signals
  • Exploit tool or code specified in 4 signals
  • PoC mentioned or linked in 7 signals
  • Patch or workaround mentioned in 32 signals
  • Technical details provided in 61 signals
  • Disclosure: 6 classified signals
  • Peaked 11d ago at 14 mentions (2026-08-19); latest day: 1
  • 64 total mentions across 13 days

Affected systems

Vendors
Products
mlflow

Deep dive

Activity timeline64 mentions / 13d
0471114Mentions · 2026-08-18: 12Mentions · 2026-08-19: 14Mentions · 2026-08-20: 13Mentions · 2026-08-21: 9Mentions · 2026-08-22: 2Mentions · 2026-08-24: 5Mentions · 2026-08-25: 2Mentions · 2026-08-26: 2Mentions · 2026-08-27: 1Mentions · 2026-08-28: 1Mentions · 2026-08-30: 1Mentions · 2026-09-02: 1Mentions · 2026-09-03: 1PoC Mentioned / Linked · 2026-08-18: 2PoC Mentioned / Linked · 2026-08-19: 2PoC Mentioned / Linked · 2026-08-20: 1PoC Mentioned / Linked · 2026-08-21: 1PoC Mentioned / Linked · 2026-08-24: 1Exploit Tool / Code · 2026-08-18: 1Exploit Tool / Code · 2026-08-19: 2Exploit Tool / Code · 2026-08-24: 1Active Exploitation · 2026-08-18: 9Active Exploitation · 2026-08-19: 11Active Exploitation · 2026-08-20: 9Active Exploitation · 2026-08-21: 8Active Exploitation · 2026-08-22: 1Active Exploitation · 2026-08-24: 2Active Exploitation · 2026-08-25: 2Active Exploitation · 2026-08-26: 1Active Exploitation · 2026-08-27: 1Active Exploitation · 2026-09-02: 1Active Exploitation · 2026-09-03: 1Patch / Workaround · 2026-08-18: 8Patch / Workaround · 2026-08-19: 5Patch / Workaround · 2026-08-20: 6Patch / Workaround · 2026-08-21: 6Patch / Workaround · 2026-08-24: 2Patch / Workaround · 2026-08-25: 2Patch / Workaround · 2026-08-26: 1Patch / Workaround · 2026-08-28: 1Patch / Workaround · 2026-08-30: 1Technical Details · 2026-08-18: 12Technical Details · 2026-08-19: 14Technical Details · 2026-08-20: 12Technical Details · 2026-08-21: 9Technical Details · 2026-08-22: 2Technical Details · 2026-08-24: 4Technical Details · 2026-08-25: 1Technical Details · 2026-08-26: 2Technical Details · 2026-08-27: 1Technical Details · 2026-08-28: 1Technical Details · 2026-08-30: 1Technical Details · 2026-09-02: 1Technical Details · 2026-09-03: 108-1808-1908-2008-2108-2208-2408-2508-2608-2708-2808-3009-0209-03
Signal classification6 categories
Active Exploitation
4367.2%
Patch
914.1%
Disclosure
69.4%
PoC
34.7%
General
23.1%
Exploit
11.6%
Referenced assets80 URLs
By indicator
Classification over time
DateTotalLabels
2026-08-1812
Active Exploitation7Disclosure2Patch1PoC2
2026-08-1914
Active Exploitation11Disclosure1Patch1PoC1
2026-08-2013
Active Exploitation9Disclosure2General1Patch1
2026-08-219
Active Exploitation8Patch1
2026-08-222
Active Exploitation1Disclosure1
2026-08-245
Active Exploitation1Exploit1General1Patch2
2026-08-252
Active Exploitation2
2026-08-262
Active Exploitation1Patch1
2026-08-271
Active Exploitation1
2026-08-281
Patch1
2026-08-301
Patch1
2026-09-021
Active Exploitation1
2026-09-031
Active Exploitation1
Full discourse20 posts
  • watchTowr@watchtowrcyber
    Active Exploitation

    🚨An unauthenticated SSRF vulnerability in MLflow, CVE-2026-64849, is already being exploited in the wild. Within hours of CVE assignment, watchTowr Intel via Attacker Eye, our global honeypot network, observed attackers targeting cloud-hosted MLflow systems in an attempt to extract credentials and secrets. All versions before 3.15.0 affected. Prioritize patching, monitor for compromise, review if sensitive credentials were exposed.

    Post summary

    CVE-2026-64849 is an unauthenticated SSRF vulnerability in MLflow that is already being actively exploited; all versions prior to 3.15.0 need immediate patching and monitoring.

    011157135.4K
    13.1K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 Attackers are exploiting an MLflow flaw to steal cloud credentials. CVE-2026-64849 lets them reach internal cloud metadata services and extract secrets. Researchers detected scanning within hours of the CVE assignment. Read: https://thehackernews.com/2026/08/attackers-exploit-mlflow-ssrf-flaw-to.html

    Post summary

    Attackers are actively exploiting the MLflow SSRF flaw (CVE-2026-64849) to steal cloud credentials; researchers note ongoing scanning shortly after the CVE's public assignment.

    574441127.2K
    2.4M followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️We added MLflow server-side request forgery vulnerability CVE-2026-64849 to our Known Exploited Vulnerabilities Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/g7l1aTUIbA

    Post summary

    The tweet announces that CVE-2026-64849, a server‑side request forgery in MLflow, has been added to a known exploited vulnerabilities catalog and urges applying mitigations to defend against ongoing attacks.

    3501608.1K
    302.8K followersView on X
  • Hackread.com@HackRead
    Active Exploitation

    Attackers are exploiting a critical MLflow bug to reach internal systems and cloud metadata, putting cloud secrets at risk. CISA has added CVE-2026-64849 to its KEV catalog. Listen/Read: https://hackread.com/attackers-exploit-critical-mlflow-ai-platform-flaw/ #CyberSecurity #MLflow #AI #Vulnerability #CISA

    Post summary

    CISA has added CVE-2026-64849 to its KEV list after reports that attackers are actively exploiting a critical MLflow bug, threatening internal and cloud secrets.

    1201722.8K
    114.1K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-64849 - critical 🚨 MLflow Webhook SSRF - Unauthenticated Full-Read via Redirect Bypass > MLflow > 3.15.0 contains an information disclosure vulnerability caused by improper v... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-64849 @pdnuclei #NucleiTemplate...

    Post summary

    The tweet announces a critical SSRF information‑disclosure vulnerability in MLflow Webhooks, detailing the attack vector but not providing a PoC, exploit code, or patch information.

    040134760
    1.3K followersView on X
  • korz3yn@webenstein_
    Active Exploitation

    Critical MLflow SSRF vulnerability being actively exploited. CVE-2026-64849 carries a CVSS score of 9.3 and can allow attackers to reach internal cloud metadata services, potentially exposing cloud credentials and secrets. CISA has added it to the KEV catalog.

    Post summary

    The post highlights that CVE-2026-64849, a critical MLflow SSRF vulnerability, is actively exploited in the wild, with a CVSS score of 9.3 and is listed in CISA's KEV catalog.

    020105786
    7.5K followersView on X
  • ThreatWire@ThreatWire_
    PoC

    🚨 CRITICAL: A public PoC is now available for CVE-2026-64849, an unauthenticated MLflow SSRF vulnerability rated CVSS 9.3. watchTowr reports that exploitation attempts have already been observed, increasing the risk for exposed MLflow deployments. 🔗 https://github.com/mlflow/mlflow/security/advisories/GHSA-7gwp-5pfp-969j #MLflow #CVE #SSRF #PoC #AI #CyberSecurity #Infosec

    Post summary

    A publicly available PoC for CVE‑2026‑64849 has been released, evidence of active exploitation exists, and the vulnerability is a high‑severity SSRF.

    010781.9K
    1.6K followersView on X
  • kokumօtօ@__kokumoto
    Active Exploitation

    米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログにMLflowのSSRF脆弱性CVE-2026-64849を追加。対処期限は3日後の9/2。ランサムウェアによる悪用は不知。 https://www.cisa.gov/news-events/alerts/2026/08/19/cisa-adds-one-known-exploited-vulnerability-catalog 差分:https://kev.kokumoto.com/#/cveId:CVE-2026-64849

    Post summary

    CISA reports CVE‑2026‑64849, an SSRF flaw in MLflow, as a known exploited vulnerability with a remediation deadline, indicating active exploitation but no PoC or exploit code was shared.

    01051857
    7.8K followersView on X
  • Aikido Community Japan@AikidoCommJP
    Active Exploitation

    AIの基盤に使うツールが、クラウド全体への侵入口になる。 そんな脆弱性が、いま実際に狙われています。 対象は MLflow。 AI・機械学習の実験結果やモデルを管理するために広く使われているOSSです。 見つかったのは、CVE-2026-64849(CVSS 9.3)。 問題を簡単に言うと、 外部からMLflowに細工したリクエストを送ると、MLflowサーバー自身に、本来アクセスさせてはいけないクラウド内部の情報を取りに行かせることができる。 というものです。 そしてクラウド環境には、サーバー自身がAWSやAzure、GCPなどを利用するための「認証情報」が置かれている場合があります。 攻撃者が狙うのは、AIモデルそのものではありません。 クラウドを操作するための鍵です。 その鍵を取られると、被害はMLflowだけでは終わりません。 権限の範囲によっては、 ・クラウドストレージ ・データベース ・別のサーバー ・他のワークロード へアクセスされる可能性があります。 つまり、 AI基盤への侵入が、クラウド環境全体への足掛かりになる。 ここが怖いところです。 しかも、単なる「理論上の脆弱性」ではありません。 watchTowrの観測では、8月17日に情報が出てから数時間以内にインターネット上で無差別な探索が始まり、クラウド上のMLflowから認証情報を取得しようとする攻撃も確認されています。 特に確認してほしいのは、 MLflow Serverをインターネットからアクセスできる状態で動かしていないか。 そして、 認証なしでアクセスできる状態になっていないか。 です。 対象は MLflow 3.15.0未満。 まず3.15.0以降へアップデート。 ただし、外部公開していた環境はアップデートだけで終わりではありません。 すでに認証情報を抜かれている可能性も考えて、 アクセスログの確認と、MLflowサーバーが持っていたクラウド認証情報のローテーションまで。 「AIのセキュリティ」というと、モデルへの攻撃やプロンプトインジェクションに目が向きます。 でも実際のAI基盤は、クラウドのストレージやDB、認証情報とつながっています。 AI基盤を守るということは、その後ろにあるクラウド全体を守ることでもあります。 #MLflow #AIセキュリティ #クラウドセキュリティ #AppSec #脆弱性

    Post summary

    The post highlights that CVE‑2026‑64849 in MLflow is already being exploited in the wild, urging immediate upgrades and credential rotations to protect underlying cloud environments.

    10033760
    860 followersView on X
  • Misbar | مسبار@MisbarSec
    Active Exploitation

    📌 وكالة الأمن السيبراني الأمريكية CISA تضيف ثغرة MLflow إلى كتالوج الثغرات المستغلة 🛡️ الفئة: ثغرة 📝 الملخص: أدرجت وكالة الأمن السيبراني والبنية التحتية الأمريكية (CISA) الثغرة CVE-2026-64849 في كتالوج Known Exploited Vulnerabilities. تُصنّف الثغرة كـ SSRF حرجة في MLflow، وتحمل درجة CVSS 9.3، ما يمكن المهاجمين من توجيه طلبات خادمية إلى موارد داخلية غير مصرح بها. تستهدف الثغرة الأنظمة التي تُشغّل MLflow أو تعتمد على مكوّن Progress LoadMaster المتصل به. دعت CISA الجهات المتأثرة إلى تطبيق التصحيحات الفورية وتفعيل مراقبة الشبكة للحد من الاستغلال. 🗓️ تاريخ النشر: 20/08/2026 🔗 للمزيد: https://securityaffairs.com/?p=197558

    Post summary

    The post announces that CVE-2026-64849, a critical SSRF flaw in MLflow, is currently being exploited in the wild (as per CISA’s catalog) and recommends immediate patching and network monitoring.

    00051566
    436 followersView on X
  • Cyber Edition@CyberEdition
    Active Exploitation

    ☁️ Attackers are actively exploiting MLflow CVE-2026-64849, an unauthenticated SSRF flaw. Cloud-hosted MLflow servers could expose internal services, metadata and temporary credentials. Upgrade to 3.15.0+ now. #CyberSecurity #CloudSecurity Read more: https://thecyberedition.com/critical-mlflow-ssrf-flaw-cve-2026-64849-exploited-in-cloud-attacks/

    Post summary

    An unauthenticated SSRF flaw in MLflow (CVE-2026-64849) is actively being exploited, potentially exposing internal services; users are urged to upgrade to 3.15.0+ to mitigate the risk.

    00060167
    767 followersView on X
  • Machina Record@MachinaRecord
    Patch

    【リンク集:週末のセキュリティ関連ニュース/記事】 <脆弱性> ・シスコ、CrossworkとSecure Workloadに存在する脆弱性9件を修正 うち5件はCVSS 10.0(CVE-2026-20030、CVE-2026-20357他) https://thehackernews.com/2026/08/cisco-patches-nine-crosswork-and-secure.html ・MLFlowの重大な欠陥が悪用される 月間3,000万回ダウンロードされるAIプラットフォーム(CVE-2026-64849) https://hackread.com/attackers-exploit-critical-mlflow-ai-platform-flaw/ ・米CISA、悪用されているTrueConfサーバーの脆弱性へのパッチ適用を連邦政府機関に命じる(CVE-2026-72529、CVE-2026-72530) https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-trueconf-server-flaws/ ・ライブラリ「isolated-vm」の重大な脆弱性により、ホスト上でRCEが可能に https://www.securityweek.com/critical-isolated-vm-vulnerability-leads-to-rce-on-host/ ・マイクロソフト、最大深刻度の脆弱性を複数修正 コード実行や権限昇格を許す恐れ(CVE-2026-69836、CVE-2026-65816他) https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-of-max-severity-entra-id-flaw-exploited-in-attacks/ <マルウェア・その他脅威> ・Androidマルウェア「ToxicPanda」 VPN権限を悪用してGoogle Playをブロック https://www.bleepingcomputer.com/news/security/toxicpanda-android-malware-uses-vpn-permissions-to-block-google-play/ ・AndroidマルウェアがFirebaseを悪用し、ICICI・SBI・Axisなどインド各銀行になりすまし 政府の無効化通知で明らかに https://ministryofcyberaffairs.com/news/indian-banks-including-icici-sbi-axis-impersonated-by-android-malware-using-firebase-government-blocking-notices-show-48362865-20a2-4665-9df6-09386ad3e106 ・Microsoft Teams悪用のフィッシング攻撃で新マルウェア「SynkLoader」が拡散される https://www.bleepingcomputer.com/news/security/new-synkloader-malware-pushed-in-microsoft-teams-phishing-campaign/ ・車のヘッドユニット狙うマルウェアが発見される https://securelist.com/android-head-unit-malware/121106/ ・FTPバナーを悪用し、新種のWindows向けマルウェアが配布される https://www.bleepingcomputer.com/news/security/hackers-abuse-ftp-server-banners-to-deliver-new-windows-malware/ ・人気AIブランド装い、マルウェアを拡散する攻撃が複数確認される https://www.helpnetsecurity.com/2026/08/21/ai-brand-impersonation-malware-malware-research/ ・偽マネーロンダリング対策サイト、ユーザーを騙して暗号通貨の取引を承認させる https://hackread.com/fake-aml-sites-crypto-approving-malicious-transactions/ ・1万ドルで販売されるフィッシングキット、パスキー登録で乗っ取ったアカウントへの永続的なアクセスが可能と主張 https://www.theregister.com/cyber-crime/2026/08/21/10k-phishing-kit-claims-it-can-plant-rogue-passkeys-for-persistent-access-to-pwned-accounts/5291006 ・トロイの木馬化された14件のnpmパッケージ、AI活用するC2機能備えたLinux向けバックドアRedC2 4.0を配布 https://thehackernews.com/2026/08/14-trojanized-npm-packages-drop-redc2.html ・バンキング型トロイの木馬Manic・Grandoreiro・ToxicPanda 2.0の詳細 https://www.securityweek.com/banking-trojans-manic-grandoreiro-toxicpanda-2-0-in-the-spotlight/ <データ侵害/サイバー犯罪> ・トロント小児病院のデータ侵害で職員と求職者の情報が流出 https://www.bleepingcomputer.com/news/security/sickkids-data-breach-exposes-employee-and-job-applicant-info/ ・米PE投資会社アポロがデータ侵害の発生を認める 金融大手狙ったハッキング攻撃が相次ぐさなか https://techcrunch.com/2026/08/21/private-equity-firm-apollo-confirms-data-breach-amid-hacking-wave-targeting-financial-giants/ <AI関連> ・暗号化されたプロンプトでGrokやGeminiの安全対策が破られる恐れ https://www.securityweek.com/encrypted-prompts-bypass-ai-safety-guardrails-in-grok-and-gemini/ ・自システムへの模擬攻撃にAIを活用しなければ、その隙を攻撃者に突かれることに https://www.theregister.com/security/2026/08/22/if-youre-not-using-ai-to-attack-your-own-systems-your-adversaries-will/5291346 ・暴走したAIモデルを制御する方法、最先端の研究所も依然明らかにせず https://techcrunch.com/2026/08/22/frontier-ai-labs-still-wont-say-how-theyd-contain-a-rogue-model/ ・OWASP、新セキュリティ指針でAIスキルの主要なリスクを指摘 https://www.darkreading.com/application-security/owasp-flags-top-ai-skill-risks-security-blueprint ・OpenAI、制御機能を複数追加 本来ならすでに実装されているべき? https://www.darkreading.com/application-security/openai-adds-controls-already ・AIのサイバー攻撃能力をベンチマークテストで順位付け https://www.aikido.dev/blog/ai-model-benchmarks-aug-21-2026 ・詳細不明のAIモデル「Ox Alpha」無料版、コーディングベンチマークでトップに https://startupfortune.com/a-mystery-model-called-ox-alpha-just-topped-coding-benchmarks-for-free/ ・AI企業が書籍を廃棄しているとして、複数の活動団体が米連邦取引委員会に苦情 https://www.theregister.com/ai-and-ml/2026/08/21/ai-companies-are-burning-books-advocates-complain-to-ftc/5291299 <サイバー戦/APT/国家型アクター/地政学関連> ・イラン系ハッカーの攻撃で英発電所が4日間停止 米水道施設への攻撃と同時期に発生 https://securityaffairs.com/197734/cyber-warfare-2/uk-power-plant-disabled-for-four-days-by-iran-linked-hackers-concurrent-with-us-water-attacks.html ・米政府の研究所が中国製LiDARにおけるセキュリティ上の欠陥を調査 https://techcrunch.com/2026/08/21/us-government-lab-is-probing-chinese-lidar-for-security-vulnerabilities/ <逮捕/テイクダウン/制裁/違反/その他法執行関連> ・Uberに8億2,500万ユーロの制裁金 ドライバーのアカウント自動停止をめぐるGDPR違反で https://techcrunch.com/2026/08/23/uber-faces-fine-of-nearly-1b-over-automated-driver-suspensions/ ・インド政府、銀行詐欺に関連するGoogle Firebaseアカウントの削除を命じる https://www.reuters.com/world/india/india-orders-removal-google-firebase-accounts-after-spotting-scam-pattern-2026-08-21/ <プライバシー> ・アリババ、ユーザー追跡目的でWebAudio使いフィンガープリンティングを作成 https://cyberinsider.com/alibaba-spotted-using-webaudio-fingerprinting-for-user-tracking/ ・TikTok、児童のプライバシー侵害訴訟で和解金4億米ドルの支払いに合意 https://techcrunch.com/2026/08/21/tiktok-reaches-400m-settlement-over-childrens-privacy-lawsuit/ ・米上院議員、法執行機関のハッキングツール使用法について見直すよう監査機関に要請 https://techcrunch.com/2026/08/21/senator-asks-us-federal-watchdog-to-review-how-feds-use-hacking-tools/ <リサーチ/攻撃手法/TTP> ・脅威インテリジェンス:Xユーザー狙ったDMCA関連の認証情報フィッシング https://ministryofcyberaffairs.com/news/threat-intelligence-dmca-themed-credential-phishing-targeting-x-twitter-users-cf7df827-ab3b-4ffc-a556-1c293a83d814 ・Windowsの名前付きパイプに危機 プロセス間通信を保全する方法 https://www.bleepingcomputer.com/news/security/named-pipes-under-attack-securing-windows-interprocess-communication/ ・漏洩状態のAWSキー数百件、悪用されれば企業アカウントの完全な乗っ取りが可能に https://www.bleepingcomputer.com/news/security/hundreds-of-leaked-aws-keys-give-full-control-over-corporate-accounts/ ・Microsoft Defenderの正規ドライバー、起動時にセキュリティソフトを削除する攻撃ツールとして悪用される可能性 https://thehackernews.com/2026/08/microsoft-defenders-own-driver-can-be.html <その他> ・「EchoBench」で自律型ペネトレーションテストツールを評価 人間による実測値を基準としたベンチマーク https://www.netspi.com/blog/technical-blog/ai-ml-pentesting/introducing-echobench-a-human-calibrated-benchmark-for-autonomous-pentesting/

    Post summary

    The article summarizes recent vulnerability disclosures, many with confirmed patches and active exploitation, highlighting the importance of timely remediation.

    010223.6K
    1.3K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(08/19追加) 🛡CVE-2026-64849 MLflow Server-Side Request Forgery Vulnerability ✅概要 ・深刻度:緊急 9.3 (CVSS Base) / GitHub, Inc. (CNA) ・種別:サーバサイドのリクエストフォージェリ (CWE-918) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N MLflow 3.15.0 未満に存在する、Webhook 配信処理におけるサーバサイドリクエストフォージェリの脆弱性です。 未認証の攻撃者が、検証を通過した外部 HTTPS URL から内部サービスやクラウドメタデータサービスへリダイレクトさせることで、MLflow サーバーから内部宛てのリクエストを送信させ、そのレスポンスを取得できる可能性があります。 MLflow 3.15.0 で修正されています。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ✅CISA 評価 ・攻撃自動化:自動化は可能 ・技術的影響:完全制御 ・BOD 26-04 対処期限(露出あり):2026年8月22日 ・BOD 26-04 対処期限(露出なし):2026年9月2日 ✅攻撃前提条件 ・MLflow 3.15.0 未満を使用している ・攻撃者が MLflow Tracking Server へネットワーク経由でアクセスできる ・Webhook test endpoint が利用可能である ・攻撃者が制御する外部 HTTPS サーバーから内部サービスやクラウドメタデータサービスへリダイレクトできる ・MLflow 3.15.0 以降へ更新されていない ✅悪用時影響 ・内部ネットワーク上の HTTP サービスへリクエストを送信される可能性がある ・クラウドインスタンスのメタデータサービスへアクセスされる可能性がある ・クラウド認証情報や内部サービス上の機密情報を取得される可能性がある ・内部ネットワーク上のホストやサービスの探索に悪用される可能性がある ・内部サービスに対して攻撃者が制御するリクエストを送信される可能性がある ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開済み ・ITW:確認済み(watchTowr) ・概要:watchTowr Intel は、CVE-2026-64849 の実悪用をハニーポットで観測し、クラウドメタデータサービスから認証情報や秘密情報の取得を試みる活動を確認したと公表しています。 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-64849 ・https://github.com/mlflow/mlflow/security/advisories/GHSA-7gwp-5pfp-969j ・https://github.com/mlflow/mlflow/issues/24179 ・https://github.com/mlflow/mlflow/pull/24258 ・https://github.com/mlflow/mlflow/commit/ba949522477cbd5915aa55d29b0cfad7d5ddf939 ・https://github.com/mlflow/mlflow/releases/tag/v3.15.0 ・https://github.com/cisagov/vulnrichment/blob/develop/2026/64xxx/CVE-2026-64849.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-64849 ・https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ・https://www.linkedin.com/posts/watchtowr_watchtowr-intel-is-observing-in-the-wild-activity-7495481580723838976-qzUA/ ・https://jvndb.jvn.jp/ja/cwe/CWE-918.html CISA Alert ・https://www.cisa.gov/news-events/alerts/2026/08/19/cisa-adds-one-known-exploited-vulnerability-catalog #vulnerability

    Post summary

    The post confirms that CVE‑2026‑64849 is actively exploited, with PoC evidence, and highlights available patch information.

    000404.3K
    44.3K followersView on X
  • اخبار داغ امنیت شبکه - تاکیان@Takianco
    Active Exploitation

    🔴 مهاجمان از یک نقص بحرانی SSRF در پلتفرم متن‌باز هوش مصنوعی MLflow (شناسه CVE-2026-64849، امتیاز ۹.۳) برای دسترسی مستقیم به سرویس‌های متادیتای ابری و سرقت اعتبارنامه‌ها سوءاستفاده می‌کنند. #CyberSecurity #MLflow #SSRF #CloudSecurity #FUXA https://www.takian.ir/news/new-%D9%85%D9%87%D8%A7%D8%AC%D9%85%D8%A7%D9%86-%D8%A7%D8%B2-%D9%86%D9%82%D8%B5-ssrf-%D8%AF%D8%B1-mlflow-%D8%A8%D8%B1%D8%A7%DB%8C-%D8%B3%D8%B1%D9%82%D8%AA-%D8%A7%D8%B9%D8%AA%D8%A8%D8%A7%D8%B1%D9%86%D8%A7%D9%85%D9%87%E2%80%8C%D9%87%D8%A7%DB%8C-%D8%A7%D8%A8%D8%B1%DB%8C-%D8%B3%D9%88%D8%A1%D8%A7%D8%B3%D8%AA%D9%81%D8%A7%D8%AF%D9%87-%D9%85%DB%8C%E2%80%8C%DA%A9%D9%86%D9%86%D8%AF https://t.co/0FPAToPxBD

    Post summary

    The post reports that attackers are actively exploiting a critical SSRF vulnerability in MLflow (CVE-2026-64849) to steal credentials from cloud metadata services, highlighting ongoing real‑world exploitation.

    00031104
    642 followersView on X
  • YourDailyCVE@YourDailyCVE
    Active Exploitation

    🚨 CVE-of-the-Day: CVE-2026-64849 — MLflow, unauthenticated Server-Side Request Forgery (SSRF) to cloud credential theft CVSS: 9.3 | EPSS: 28% MLflow's webhook feature validates a URL once at registration but doesn't recheck it on delivery — letting an attacker redirect requests to internal cloud metadata endpoints and steal IAM credentials. No login needed. Actively exploited within hours of disclosure. #CVE #cloudsecurity #MLflow

    Post summary

    The tweet discloses CVE-2026-64849, a critical unauthenticated SSRF in MLflow allowing cloud credential theft, and explicitly reports that active exploitation occurred within hours of disclosure.

    10020104
    32 followersView on X
  • Adam@seoscottsdale
    Active Exploitation

    1/4 🚨 CYBER LANDSCAPE SNAPSHOT – Aug 20, 2026 Last 24h: CISA drops fresh KEV on critical MLflow SSRF (CVE-2026-64849). Cloud creds at risk. Medusa ransomware now confirmed >500 critical infra victims. Citrix NetScaler auth-bypass + DoS flaws need immediate patches. Windows IKE RCE actively exploited. Thread 🧵 Save this. @grok

    Post summary

    The message highlights that Windows IKE RCE is being actively exploited, announces a new KEV for MLflow SSRF, and urges immediate patching of identified Citrix NetScaler flaws.

    21000205
    12.4K followersView on X
  • O3 Security@O3security
    Active Exploitation

    🚨 MLflow SSRF is being exploited. CVE-2026-64849 → attackers reaching cloud metadata services → stealing credentials. Scanning started within hours of the CVE drop. Patch to 3.15.0 now. https://t.co/GOJrSgf5z5

    Post summary

    CVE-2026-64849 (MLflow SSRF) is actively exploited to reach cloud metadata services and steal credentials; a patch to version 3.15.0 is now available.

    00120299
    33 followersView on X
  • كاسبر سكاي@KasperskyDev
    Active Exploitation

    ثغرة حرجة في ملفلو تُستغل فعلياً لسرقة بيانات اعتماد هوية السحابة دون أي صلاحيات. المعرّف : CVE-2026-64849 درجة الخطورة : Critical - Actively Exploited الإصدارات المتأثرة : MLflow < 3.15.0 الحل : Upgrade to MLflow 3.15.0 #MLflow #CVE202664849

    Post summary

    CVE-2026-64849 is a critical vulnerability in MLflow that is actively exploited to exfiltrate cloud identity credentials; upgrading to version 3.15.0 mitigates the risk.

    11000217
    39.9K followersView on X
  • Vikram Dias@BigVikDada
    Active Exploitation

    CVE-2026-64849 in MLflow is live in the wild. DNS rebinding + malicious webhooks → cloud keys. If you’re still on older versions, treat it as active risk. An SSRF vulnerability (CVE-2026-64849) is being actively exploited. Attackers can use DNS rebinding and malicious webhook redirects to steal cloud credentials without authentication. If you have MLflow exposed or reachable in any environment that holds cloud credentials, assume the window is already open. Patch to 3.15.0 or later, restrict network access to the service, and review logs for unexpected webhook or outbound DNS activity. This is the pattern that keeps repeating with ML and AI tooling: features that talk to the outside world (webhooks, callbacks, model registries) become credential exfil paths when auth and validation are weak. Have you already confirmed every MLflow instance is on 3.15.0+, or is this still sitting in the backlog? #InfoSec #MLflow #CloudSecurity

    Post summary

    CVE‑2026‑64849 is an actively exploited SSRF in MLflow, leveraging DNS rebinding and malicious webhook redirects to exfiltrate cloud credentials. Urgent action is advised: upgrade to 3.15.0+ or restrict network exposure.

    0001171
    157 followersView on X
  • KweenB@kweenbhacks
    General

    @0x686967 https://nvd.nist.gov/vuln/detail/CVE-2026-64849

    Post summary

    The tweet only references the CVE via a link to the NVD page, providing no additional information.

    1001042
    39 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applfprojectsmlflow---

Explore more