CISA has detected active exploitation of CVE-2026-64849, a critical SSRF in MLflow. Exposed tracking servers without authentication can be abused to query cloud metadata, internal services, and loopba

CISA has detected active exploitation of CVE-2026-64849, a critical SSRF in MLflow. Exposed tracking servers without authentication can be abused to query cloud metadata, internal services, and loopback addresses, leading to credential theft and internal reconnaissance. # CloudSecurity # SSRF # Vulnerability # ThreatIntel https:// cyberworldops.eu/en/mlflow-und er-attack-critical-ssrf-exposes-clou

1 reportother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

CISA has detected active exploitation of CVE-2026-64849, a critical SSRF in MLflow. Exposed tracking servers without authentication can be abused to query cloud metadata, internal services, and loopba

mastodon:infosec-exchangeother40d ago kagi ↗

CISA has detected active exploitation of CVE-2026-64849, a critical SSRF in MLflow. Exposed tracking servers without authentication can be abused to query cloud metadata, internal services, and loopback addresses, leading to credential theft and internal reconnaissance. # CloudSecurity # SSRF # Vulnerability # ThreatIntel https:// cyberworldops.eu/en/mlflow-und er-attack-critical-ssrf-exposes-clou