Attackers are actively exploiting CVE-2026-64849, a critical unauthenticated server-side request forgery flaw in MLflow’s webhook delivery logic, to steal credentials and sensitive data from exposed tracking server deployments. The vulnerability affects MLflow versions prior to 3.15.0 and abuses the default-enabled model-registry webhooks API, allowing crafted webhook requests to reach internal services and cloud metadata endpoints. Researchers reported exploitation within hours of the CVE being assigned, with attempts to extract secrets from addresses including 127.0.0.1 and 169.254.169.254.
The flaw stems from MLflow validating a webhook URL and then re-resolving or following redirect targets during delivery, enabling DNS rebinding or redirect-based access to non-public destinations. Successful exploitation can expose highly privileged credentials, including AWS IAM role credentials tied to EC2 instances or Kubernetes nodes, and may provide access to internal databases, configurations, and administrative tools. The vulnerability carries a CVSS 9.3 rating, and MLflow 3.15.0 addresses it by tightening destination validation and blocking non-global IP addresses; defenders are being urged to patch immediately and investigate whether secrets or cloud credentials were exposed.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
CISA updated its Known Exploited Vulnerabilities catalog on 2026-08-19 to add CVE-2026-64849, the MLflow server-side request forgery flaw. The listing confirms known exploitation and directs organizations to apply vendor mitigations under BOD 26-04 guidance.
VulnCheck detected malicious internet-wide scanning for FUXA CVE-2026-25895 on August 18, 2026. The activity targeted exposed FUXA instances with requests attempting to overwrite main.js via path traversal, though no remote code execution payloads had been observed yet.
A public GitHub issue disclosed a critical MLflow SSRF vulnerability in outbound webhook delivery caused by a DNS rebinding TOCTOU gap. The report described how an authenticated user could abuse webhook creation to reach cloud metadata and internal services, and proposed validating the connected peer IP at socket time.
MLflow maintainers fixed CVE-2026-64849 in version 3.15.0. The patch adds peer-socket verification and blocks non-global destination IPs before allowing webhook delivery.
Public reporting explained that MLflow validates webhook URLs but does not pin or re-validate the final destination, enabling SSRF through DNS rebinding and HTTP redirects. The issue can expose internal resources such as localhost services and cloud metadata endpoints, with reflected responses leaking retrieved data back to the attacker.
watchTowr Labs reported observing attackers target cloud-hosted MLflow systems within hours of CVE assignment. The exploitation attempts sought to extract credentials and other secrets from exposed deployments.
A critical unauthenticated SSRF vulnerability in MLflow webhook handling was identified as CVE-2026-64849. The flaw affects versions prior to 3.15.0 and can be abused to reach internal services and cloud metadata endpoints.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
16 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourcebleepingcomputer.com
Open sourcesecurityaffairs.com
Open sourcemalware.news
Open sourcecvereports.com
Open sourcecve.org
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.