The Cybersecurity and Infrastructure Security Agency (CISA) has warned federal agencies that threat actors are actively exploiting a critical MLflow vulnerability that can expose internal services and cloud credentials.
MLflow is a Linux Foundation-backed, open-source AI engineering platform used to develop, evaluate, optimize, and monitor large language models (LLMs) and AI agents. The platform receives more than 30 million monthly downloads and is used by thousands of organizations.
Tracked as CVE-2026-64849, the critical DNS rebinding and server-side request forgery (SSRF) vulnerability affects MLflow’s outbound webhook delivery feature. The flaw is patched in MLflow version 3.15.0 and can allow an unauthenticated, unprivileged attacker to remotely access internal services or cloud metadata from an unpatched server.
According to an MLflow security advisory issued three weeks ago, the default MLflow tracking server runs without authentication and uses a default SQLite backend. This configuration exposes an unauthenticated model registry webhook API, including the synchronous POST /api/2.0/mlflow/webhooks/{id}/test endpoint, which returns the upstream response status and body to the requester.
An attacker who can reach the MLflow tracking server could use the vulnerability to make HTTP requests to arbitrary internal, loopback, or cloud metadata endpoints. The attacker may then read the responses through the vulnerable test endpoint, potentially accessing AWS Instance Metadata Service (IMDS) credentials, internal management services, and information useful for scanning internal hosts and ports.
A successful exploit could allow attackers to steal cloud credentials, including Amazon Web Services (AWS) Identity and Access Management (IAM) credentials, through a low-complexity attack that does not require authentication.
CVE-2026-64849 added to CISA’s Known Exploited Vulnerabilities catalog
On Wednesday, CISA added CVE-2026-64849 to its Known Exploited Vulnerabilities (KEV) catalog. The agency also ordered U.S. Federal Civilian Executive Branch (FCEB) agencies to secure vulnerable MLflow instances within two weeks, as required by Binding Operational Directive 26-04.
Issued in June, BOD 26-04 requires U.S. government agencies to prioritize remediation when vulnerabilities are publicly disclosed, added to CISA’s KEV catalog, exploitable through automated attacks, or capable of giving attackers partial or complete control of affected systems.
Although BOD 26-04 applies only to U.S. government agencies, CISA urged all network defenders to prioritize patching and mitigation for MLflow systems exposed to attacks targeting CVE-2026-64849.
“These types of vulnerabilities are a frequent attack vector for malicious cyber attackers and pose significant risks to federal enterprises,” CISA warned. “Stakeholders are responsible for assessing each asset’s Internet exposure and ensuring compliance with BOD 26-04 patching guidelines.”
CISA also warned Tuesday that hackers are exploiting a high-severity remote code execution (RCE) vulnerability in the Windows Internet Key Exchange (IKE) service extension component.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




