INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

MLflow SSRF Exploit Attack

| 2026-08-20 08:55 CRITICAL HIGH
Executive Summary AI-generated
The newly discovered vulnerability in MLflow, a popular AI engineering platform used by thousands of organizations, has been identified as CVE-2026-64849. This critical DNS-rebinding server-side request forgery (SSRF) bypass flaw allows attackers to remotely access internal services or cloud metadata configurations on unpatched instances without privileges. The Cybersecurity and Infrastructure Security Agency (CISA) has warned federal agencies about the vulnerability, which can be exploited by threat actors using a remote code execution (RCE) flaw in Windows Internet Key Exchange (IKE) Service Extensions component. This has prompted CISA to issue a security advisory and order U.S. Federal Civilian Executive Branch (FCEB) agencies to secure their MLflow instances within two weeks, as mandated by Binding Operational Directive 26-04. The vulnerability is rated critical with a CVSS score of 9.3, indicating its severity and potential impact on organizations relying on this platform.
Technical Mitigations AI-generated
* Implement secure authentication and authorization mechanisms for MLflow instances, including the use of multi-factor authentication (MFA) or token-based authentication to prevent unauthorized access. * Regularly update and patch MLflow versions to ensure that any known vulnerabilities are addressed before they can be exploited by attackers. * Monitor audit logs for signs of compromise on MLflow systems and take prompt action if suspicious activity is detected, including changing passwords and disabling unnecessary services. * Implement network segmentation and isolation techniques to limit the reach of exposed cloud metadata endpoints and prevent unauthorized access from outside the organization.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-25895CVE-2026-25895 CVE-2026-64849CVE-2026-64849 CVE-2026-25939CVE-2026-25939 CVE-2023-33831CVE-2023-33831
Target & Sectors
Global Scope technologytechnology governmentgovernment
Incident Timeline
‎November 2025
Threat actors used FUXA to target CVE-2023-33831.
vulnerability CVE-2026-25939
organisation CVE-2023-33831
‎August 17, 2026
Threat actors used Intel's MLflow flaw to target cloud-hosted instances directly, capturing attempts against cloud credentials and secrets.
organisation CVE
vulnerability CVE-2026-64849
infrastructure 1.2.9
organisation Intel
infrastructure 60 monthly downloads
‎2026/08/17
Threat actors used an MLflow flaw to target CVE-2026-25939.
vulnerability CVE-2026-25939
organisation CVE-2023-33831
‎Aug 18, 2026
Threat actors used an identified vulnerability in the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities catalog to target a specific system.
‎August 18, 2026
Threat actors used an exploit tool to target CVE-2026-25895 on August 18, 2026.
vulnerability CVE-2026-25895
‎2026/08/20
U.S. CISA adds an MLflow flaw to its Known Exploited Vulnerabilities catalog, specifically CVE-2026-64849, a server-side request forgery vulnerability in the Tracking Server (mlflow server) that allows attackers to issue HTTP requests and extract sensitive data from internal cloud metadata endpoints.
organisation MLflow
organisation CVE-2026
infrastructure 3.15.0
organisation DNS
organisation VulnCheck
infrastructure 9.5
organisation SQLite
organisation API
organisation POST
infrastructure Linux
organisation the Linux Foundation
infrastructure 30 monthly downloads
infrastructure Windows
organisation FUXA
organisation IAM
organisation AWS Identity and Access Management
organisation The Blue Report 2026
organisation IP
infrastructure 60 FUXA installations
Tactical Metrics
Metrics
infrastructure
‎3.15.0
Software Version
Metrics
infrastructure
60,000,000
Monthly Downloads
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
30,000,000
Monthly Downloads
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎9.5
Software Version
Metrics
infrastructure
‎1.2.9
Software Version
Metrics
infrastructure
60
Fuxa Installations
Intelligence Sources