CISA has detected active exploitation of CVE-2026-64849, a critical SSRF in MLflow. Exposed tracking servers without authentication can be abused to query cloud metadata, internal services, and loopba
CISA has detected active exploitation of CVE-2026-64849, a critical SSRF in MLflow. Exposed tracking servers without authentication can be abused to query cloud metadata, internal services, and loopback addresses, leading to credential theft and internal reconnaissance. # CloudSecurity # SSRF # Vulnerability # ThreatIntel https:// cyberworldops.eu/en/mlflow-und er-attack-critical-ssrf-exposes-clou