AI Stories on SHORT INFO are generated & curated with AI
3 linked sources 20 Aug, 16:10

Critical MLflow flaw actively exploited to steal cloud credentials

A critical unauthenticated SSRF flaw in MLflow, the open-source machine-learning platform, is being actively exploited to steal cloud credentials, per security firm watchTowr. CISA added it to its Known Exploited Vulnerabilities catalog on August 19.

Researchers at watchTowr say attackers began scanning for exposed MLflow servers within hours of CVE-2026-64849 being assigned on August 17, 2026. The flaw, an unauthenticated server-side request forgery bug with a CVSS score of 9.3, lets attackers abuse MLflow's model-registry webhooks to reach internal cloud metadata services and extract temporary credentials and secrets. MLflow is downloaded more than 60 million times a month, per watchTowr. The U.S. Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalog on August 19, 2026. MLflow's maintainers say version 3.15.0 resolves the issue. Sources: The Hacker News, Security Affairs, CISA.

#cyber
Published on