INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
MLflow SSRF Exploit Attack
| 2026-08-20 08:55 CRITICAL HIGHExecutive Summary AI-generated
The newly discovered vulnerability in MLflow, a popular AI engineering platform used by thousands of organizations, has been identified as CVE-2026-64849. This critical DNS-rebinding server-side request forgery (SSRF) bypass flaw allows attackers to remotely access internal services or cloud metadata configurations on unpatched instances without privileges. The Cybersecurity and Infrastructure Security Agency (CISA) has warned federal agencies about the vulnerability, which can be exploited by threat actors using a remote code execution (RCE) flaw in Windows Internet Key Exchange (IKE) Service Extensions component. This has prompted CISA to issue a security advisory and order U.S. Federal Civilian Executive Branch (FCEB) agencies to secure their MLflow instances within two weeks, as mandated by Binding Operational Directive 26-04. The vulnerability is rated critical with a CVSS score of 9.3, indicating its severity and potential impact on organizations relying on this platform.
Technical Mitigations AI-generated
* Implement secure authentication and authorization mechanisms for MLflow instances, including the use of multi-factor authentication (MFA) or token-based authentication to prevent unauthorized access.
* Regularly update and patch MLflow versions to ensure that any known vulnerabilities are addressed before they can be exploited by attackers.
* Monitor audit logs for signs of compromise on MLflow systems and take prompt action if suspicious activity is detected, including changing passwords and disabling unnecessary services.
* Implement network segmentation and isolation techniques to limit the reach of exposed cloud metadata endpoints and prevent unauthorized access from outside the organization.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-25895CVE-2026-25895
CVE-2026-64849CVE-2026-64849
CVE-2026-25939CVE-2026-25939
CVE-2023-33831CVE-2023-33831
Target & Sectors
Global Scope
technologytechnology
governmentgovernment
Incident Timeline
November 2025
Threat actors used FUXA to target CVE-2023-33831.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-25939
"
Over the past year, two other vulnerabilities in FUXA –
CVE-2026-25939
and
CVE-2023-33831
– have also witnessed active exploitation efforts, with the latter witnessing activity "dating back to November 2025 and as recently as yesterday," per Condon.
organisation
CVE-2023-33831
"
Over the past year, two other vulnerabilities in FUXA –
CVE-2026-25939
and
CVE-2023-33831
– have also witnessed active exploitation efforts, with the latter witnessing activity "dating back to November 2025 and as recently as yesterday," per Condon.
August 17, 2026
Threat actors used Intel's MLflow flaw to target cloud-hosted instances directly, capturing attempts against cloud credentials and secrets.
Click on any entity below to view its context and source!
organisation
CVE
Cybersecurity firm watchTowr also observed widespread scanning for exposed MLflow instances just hours after the CVE was assigned on August 17, 2026.
(Affects versions <= 1.2.9)
"Attackers are exploiting [CVE-2026-64849] to reach cloud metadata services directly, and exfiltrating cloud credentials and secrets," watchTowr
said
in a post on LinkedIn, adding it detected bad actors indiscriminately scanning for exposed MLflow instances online within hours of the CVE being assigned on August 17, 2026.
vulnerability
CVE-2026-64849
(Affects versions <= 1.2.9)
"Attackers are exploiting [CVE-2026-64849] to reach cloud metadata services directly, and exfiltrating cloud credentials and secrets," watchTowr
said
in a post on LinkedIn, adding it detected bad actors indiscriminately scanning for exposed MLflow instances online within hours of the CVE being assigned on August 17, 2026.
infrastructure
1.2.9
(Affects versions <= 1.2.9)
"Attackers are exploiting [CVE-2026-64849] to reach cloud metadata services directly, and exfiltrating cloud credentials and secrets," watchTowr
said
in a post on LinkedIn, adding it detected bad actors indiscriminately scanning for exposed MLflow instances online within hours of the CVE being assigned on August 17, 2026.
organisation
Intel
“
watchTowr
Intel is observing in-the-wild exploitation of a critical unauthenticated Server-Side Request Forgery vulnerability in MLflow (CVE-2026-64849), the open-source platform for managing the machine learning and AI development lifecycle, with over 60 million monthly downloads.”
infrastructure
60 monthly downloads
“
watchTowr
Intel is observing in-the-wild exploitation of a critical unauthenticated Server-Side Request Forgery vulnerability in MLflow (CVE-2026-64849), the open-source platform for managing the machine learning and AI development lifecycle, with over 60 million monthly downloads.”
2026/08/17
Threat actors used an MLflow flaw to target CVE-2026-25939.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-25939
"
Over the past year, two other vulnerabilities in FUXA –
CVE-2026-25939
and
CVE-2023-33831
– have also witnessed active exploitation efforts, with the latter witnessing activity "dating back to November 2025 and as recently as yesterday," per Condon.
organisation
CVE-2023-33831
"
Over the past year, two other vulnerabilities in FUXA –
CVE-2026-25939
and
CVE-2023-33831
– have also witnessed active exploitation efforts, with the latter witnessing activity "dating back to November 2025 and as recently as yesterday," per Condon.
Aug 18, 2026
Threat actors used an identified vulnerability in the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities catalog to target a specific system.
August 18, 2026
Threat actors used an exploit tool to target CVE-2026-25895 on August 18, 2026.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-25895
As for CVE-2026-25895, VulnCheck said it detected malicious scanning aimed at the flaw starting August 18, 2026.
2026/08/20
U.S. CISA adds an MLflow flaw to its Known Exploited Vulnerabilities catalog, specifically CVE-2026-64849, a server-side request forgery vulnerability in the Tracking Server (mlflow server) that allows attackers to issue HTTP requests and extract sensitive data from internal cloud metadata endpoints.
Click on any entity below to view its context and source!
organisation
MLflow
CVE-2026-64849 is a critical server-side request forgery (SSRF) vulnerability in MLflow, a platform for managing machine-learning workflows.
An unauthenticated Server-Side Request Forgery (SSRF) vulnerability in MLflow that can allow an attacker who can reach the Tracking Server (mlflow server) to issue HTTP requests to arbitrary internal cloud metadata endpoints and extract sensitive data.
organisation
CVE-2026
Attackers are actively exploiting CVE-2026-64849 to access cloud metadata services and steal credentials and secrets.
infrastructure
3.15.0
Tracked as
CVE-2026-64849
, this critical DNS-rebinding server-side request forgery (SSRF) bypass in MLflow's outbound webhook delivery was patched in version 3.15.0 and can be used by attackers without privileges to remotely access internal services or cloud metadata configurations on unpatched instances.
The issue affects MLflow versions before 3.15.0 and a remote attacker can exploit the issue without authentication.
(Affects versions < 3.15.0)
CVE-2026-25895
(CVSS score: 9.5) -
organisation
DNS
Tracked as
CVE-2026-64849
, this critical DNS-rebinding server-side request forgery (SSRF) bypass in MLflow's outbound webhook delivery was patched in version 3.15.0 and can be used by attackers without privileges to remotely access internal services or cloud metadata configurations on unpatched instances.
organisation
VulnCheck
According to independent reports from watchTowr and VulnCheck, the vulnerabilities in question are as follows -
CVE-2026-64849
(CVSS score: 9.3) -
infrastructure
9.5
(Affects versions < 3.15.0)
CVE-2026-25895
(CVSS score: 9.5) -
organisation
SQLite
"The default MLflow Tracking Server (mlflow server, no authentication, default SQLite backend) exposes the model-registry webhooks API unauthenticated, including a synchronous POST /api/2.0/mlflow/webhooks/{id}/test endpoint that returns the upstream response status and body to the caller," MLflow's security team
says
in a security advisory issued three weeks ago.
organisation
API
"The default MLflow Tracking Server (mlflow server, no authentication, default SQLite backend) exposes the model-registry webhooks API unauthenticated, including a synchronous POST /api/2.0/mlflow/webhooks/{id}/test endpoint that returns the upstream response status and body to the caller," MLflow's security team
says
in a security advisory issued three weeks ago.
organisation
POST
"The default MLflow Tracking Server (mlflow server, no authentication, default SQLite backend) exposes the model-registry webhooks API unauthenticated, including a synchronous POST /api/2.0/mlflow/webhooks/{id}/test endpoint that returns the upstream response status and body to the caller," MLflow's security team
says
in a security advisory issued three weeks ago.
infrastructure
Linux
MLflow is an open-source AI engineering platform for large language models (LLMs) and agents backed by the Linux Foundation, with over 30 million monthly downloads, used by thousands of organizations to debug, evaluate, optimize, and monitor AI applications.
organisation
the Linux Foundation
MLflow is an open-source AI engineering platform for large language models (LLMs) and agents backed by the Linux Foundation, with over 30 million monthly downloads, used by thousands of organizations to debug, evaluate, optimize, and monitor AI applications.
infrastructure
30 monthly downloads
MLflow is an open-source AI engineering platform for large language models (LLMs) and agents backed by the Linux Foundation, with over 30 million monthly downloads, used by thousands of organizations to debug, evaluate, optimize, and monitor AI applications.
infrastructure
Windows
"
On Tuesday, CISA warned that hackers are now also
abusing a critical-severity remote code execution (RCE) flaw
in the Windows Internet Key Exchange (IKE) Service Extensions component.
organisation
FUXA
A missing authentication for a critical function and path traversal vulnerability in FUXA that can allow an unauthenticated, remote attacker to write arbitrary files to the server file system and achieve remote code execution.
organisation
IAM
"An unauthenticated attacker who can reach the tracking server makes the server issue HTTP requests to arbitrary internal/loopback/cloud-metadata endpoints and reads the responses via /test: cloud instance-metadata (e.g. AWS IMDS IAM credentials), internal-only admin services behind the network boundary, and internal port/host scanning.
organisation
AWS Identity and Access Management
"
Successful exploitation can allow threat actors to steal cloud credentials, such as AWS Identity and Access Management (IAM) credentials, in low-complexity attacks.
organisation
The Blue Report 2026
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
organisation
IP
Evidence from our global honeypot telemetry indicates attackers are abusing this vulnerability to target cloud-hosted MLflow systems in an attempt to extract credentials and secrets from well-known internal IP addresses and services.
infrastructure
60 FUXA installations
There are about 60 FUXA installations exposed to the public internet.
Tactical Metrics
Metrics
infrastructure
3.15.0
Software Version
Click for context!
The issue affects MLflow versions before 3.15.0 and a remote attacker can exploit the issue without authentication.
Tracked as
CVE-2026-64849
, this critical DNS-rebinding server-side request forgery (SSRF) bypass in MLflow's outbound webhook delivery was patched in version 3.15.0 and can be used by attackers without privileges to remotely access internal services or cloud metadata configurations on unpatched instances.
(Affects versions < 3.15.0)
CVE-2026-25895
(CVSS score: 9.5) -
Metrics
infrastructure
60,000,000
Monthly Downloads
“
watchTowr
Intel is observing in-the-wild exploitation of a critical unauthenticated Server-Side Request Forgery vulnerability in MLflow (CVE-2026-64849), the open-source platform for managing the machine learning and AI development lifecycle, with over 60 million monthly downloads.”
Metrics
infrastructure
Linux
Affected Product
MLflow is an open-source AI engineering platform for large language models (LLMs) and agents backed by the Linux Foundation, with over 30 million monthly downloads, used by thousands of organizations to debug, evaluate, optimize, and monitor AI applications.
Metrics
infrastructure
30,000,000
Monthly Downloads
MLflow is an open-source AI engineering platform for large language models (LLMs) and agents backed by the Linux Foundation, with over 30 million monthly downloads, used by thousands of organizations to debug, evaluate, optimize, and monitor AI applications.
Metrics
infrastructure
Windows
Affected Product
"
On Tuesday, CISA warned that hackers are now also
abusing a critical-severity remote code execution (RCE) flaw
in the Windows Internet Key Exchange (IKE) Service Extensions component.
Metrics
infrastructure
9.5
Software Version
(Affects versions < 3.15.0)
CVE-2026-25895
(CVSS score: 9.5) -
Metrics
infrastructure
1.2.9
Software Version
(Affects versions <= 1.2.9)
"Attackers are exploiting [CVE-2026-64849] to reach cloud metadata services directly, and exfiltrating cloud credentials and secrets," watchTowr
said
in a post on LinkedIn, adding it detected bad actors indiscriminately scanning for exposed MLflow instances online within hours of the CVE being assigned on August 17, 2026.
Metrics
infrastructure
60
Fuxa Installations
There are about 60 FUXA installations exposed to the public internet.
Intelligence Sources
The Hacker News
2026-08-18
BleepingComputer
2026-08-20
CISA warns of hackers exploiting critical MLflow vulnerability
BleepingComputer
Security Affairs
2026-08-20
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-21T06:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
17x
attribution
Attributing Entity
The U.S. Cybersecurity and Infrastructure Security Agency
authority
16x
organisation
Identified Entity
MLflow
entity
5x
timeline
Temporal Reference
August 17, 2026
date
4x
vulnerability
Exploited CVE
CVE-2026-64849
cve
4x
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
3x
infrastructure
Software Version
3.15.0
version
2x
infrastructure
Monthly Downloads
60,000,000
monthly downloads
2x
industry
Targeted Sector
Government
sector
2x
infrastructure
Affected Product
Linux
software
Contextual Telemetry
Context Block
10 METRICS
vulnerability
CVSS Score
9
score
general metric
Cve-2026
64,849
cve-2026
general metric
Bod
26
bod
tactic
Cyber Operation Type
Remote Code Execution
tactic
general metric
Blue Report
2,026
blue report
general metric
Simulations
338,000,000
simulations
general metric
Aug
18
aug
general metric
Score
9
score
general metric
Affects Versions
10
affects versions
infrastructure
Fuxa Installations
60
fuxa installations
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.