← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 18, 2026 · 16:52via Cyber Security News

Critical MLflow SSRF Vulnerability Exploited by Hackers in the Wild

Brief

Threat actors are actively exploiting a critical, unauthenticated server-side request forgery (SSRF) vulnerability in MLflow, the popular open-source platform widely used by data engineering and machine learning teams to track experiments, package code, and deploy models.

Tracked as CVE-2026-64849 with a critical CVSS 3. 1 score of 9. 3, the flaw impacts all MLflow versions prior to 3.

  • 0.

Threat monitoring by watchTowr Intel through its global Attacker Eye honeypot sensor network identified adversaries targeting internet-exposed MLflow instances within hours of public disclosure to harvest cloud credentials and sensitive deployment tokens.

Read more on Cyber Security News