CISA Alerts: Active Exploitation of MLflow SSRF Bug
๐ The Cybersecurity and Infrastructure Security Agency (CISA) warns that threat actors are actively exploiting a critical MLflow vulnerability (CVE-2026-64849) that enables a DNS-rebinding SSRF bypass in MLflow's outbound webhook delivery. The flaw, patched in MLflow 3.15.0, allows unauthenticated attackers to make the tracking server issue requests to internal and cloud-metadata endpoints and read responses, risking theft of cloud credentials. CISA added the issue to its KEV catalog and ordered federal agencies to remediate under BOD 26-04, urging all defenders to prioritize patching.
