CISA warns hackers exploit critical MLflow SSRF flaw CVE-2026-64849
This digest was compiled by AI from multiple sources — links to the originals are below.

CISA on Wednesday added CVE-2026-64849, a critical SSRF flaw in MLflow, to its known exploited vulnerabilities catalog and ordered U.S. federal civilian agencies to patch within two weeks. watchTowr said attackers began scanning for MLflow systems within hours of the CVE assignment and are using it to reach cloud metadata services and steal credentials.
Key Facts
- CISA added CVE-2026-64849 to its Known Exploited Vulnerabilities catalog on Wednesday and ordered U.S. federal civilian agencies to secure MLflow instances within two weeks under Binding Operational Directive 26-04.
- MLflow is an open-source AI platform with more than 30 million monthly downloads, used by thousands of organizations for debugging and monitoring AI applications.
- The critical SSRF bypass in MLflow webhook delivery was patched in version 3.15.0 and can be exploited without privileges to access internal services or cloud metadata configurations.
- watchTowr said attackers began scanning for MLflow systems within hours after the CVE ID was assigned and are exfiltrating cloud credentials and secrets.
- A Thursday report from Americans for Responsible Innovation calls for designating AI models, companies and supporting industries as critical infrastructure with CISA as lead cyber agency.
Webhook SSRF Bypass
MLflow is an open-source AI engineering platform backed by the Linux Foundation with more than 30 million monthly downloads and use by thousands of organizations to debug, evaluate and monitor AI applications. CVE-2026-64849 is a critical DNS-rebinding server-side request forgery bypass in MLflow's outbound webhook delivery, patched in version 3.15.0. The default MLflow Tracking Server exposes the model-registry webhooks API unauthenticated, including a synchronous POST /api/2.0/mlflow/webhooks/{id}/test endpoint that returns upstream response status and body to the caller. An unauthenticated attacker can make the server issue HTTP requests to arbitrary internal, loopback or cloud-metadata endpoints and read the responses.
Exploitation and Response
On Wednesday, CISA added the vulnerability to its catalog of flaws exploited in the wild and ordered U.S. Federal Civilian Executive Branch agencies to secure their MLflow instances within two weeks under Binding Operational Directive 26-04. BOD 26-04, issued in June, requires agencies to prioritize patching when vulnerable assets are publicly exposed online, when a flaw is added to CISA's KEV catalog, when exploitation can be automated, or when successful exploitation gives attackers partial or total control. watchTowr revealed that attackers began scanning for MLflow systems within hours after the CVE ID was assigned. The firm said attackers are exploiting the vulnerability to reach cloud metadata services directly and exfiltrating cloud credentials and secrets. CISA also warned Tuesday that hackers are abusing a critical-severity remote code execution flaw in the Windows Internet Key Exchange Service Extensions component.
AI Critical Infrastructure Call
A report published Thursday by the nonprofit Americans for Responsible Innovation calls for the federal government to declare key AI models, companies and supporting industries as critical infrastructure. The report also calls for naming the Cybersecurity and Infrastructure Security Agency as the lead agency managing cyberthreats for the sector. The push comes as AI adoption has accelerated across federal agencies and the private sector under the Trump administration, with software developers using large language models to generate much of their code. Foreign governments are conducting cyber and kinetic attacks targeting data centers and other AI-related infrastructure.
2 sources
CISA warns hackers exploit critical MLflow SSRF flaw CVE-2026-64849



