CISA warns of hackers exploiting critical MLflow vulnerability

Cybersecurity experts are sounding the alarm as hackers begin exploiting a critical vulnerability in MLflow, an open-source platform used by thousands of organizations to build and manage artificial intelligence (AI) applications. The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning that unpatched instances of MLflow are vulnerable to attacks that can allow threat actors to steal sensitive cloud credentials.

MLflow is a widely-used platform, with over 30 million monthly downloads, and its vulnerability poses significant risks to the federal enterprise. CISA has added the flaw to its catalog of exploited vulnerabilities and ordered U.S. government agencies to secure their MLflow instances within two weeks. The agency urged all network defenders to prioritize patching against attacks targeting this vulnerability.

The critical DNS-rebinding server-side request forgery (SSRF) bypass in MLflow’s outbound webhook delivery, tracked as CVE-2026-64849, allows attackers to remotely access internal services or cloud metadata configurations on unpatched instances. This can be done without requiring privileges, making it a low-complexity attack.

The default MLflow Tracking Server exposes its model-registry webhooks API unauthenticated, allowing an attacker who can reach the tracking server to issue HTTP requests to arbitrary internal/loopback/cloud-metadata endpoints and read responses via a synchronous POST endpoint. Successful exploitation can grant attackers access to sensitive cloud credentials, such as AWS Identity and Access Management (IAM) credentials.

While CISA’s Binding Operational Directive 26-04 applies only to U.S. government agencies, the agency warned that all network defenders should prioritize patching their systems against attacks targeting this vulnerability. “This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise,” CISA stated.

In related news, CISA has also issued warnings about other critical vulnerabilities being exploited in the wild, including a remote code execution flaw in the Windows Internet Key Exchange (IKE) Service Extensions component. As these types of attacks continue to evolve, it’s essential for organizations to stay vigilant and prioritize patching against known vulnerabilities.

For those using MLflow, it’s crucial to assess their exposure and ensure they have implemented the necessary patches to mitigate this risk. Organizations should also review their security protocols and consider implementing additional measures to prevent similar attacks in the future. By staying informed and proactive, we can reduce the likelihood of successful cyberattacks and minimize potential damage.

As a practical takeaway, it’s essential for IT teams to regularly scan for vulnerabilities, apply patches promptly, and maintain up-to-date software configurations. This will help prevent attackers from exploiting known weaknesses and ensure that organizations remain secure in an ever-evolving threat landscape.


Source: Bleeping Computer — 2026-08-20