Wire · opportunities
Active Exploitation of MLflow SSRF Vulnerability (CVE-2026-64849) Enables Cloud ...
◆ Sectors
◆ Source
◆ Verified
Fusion42 · 21 August 2026 · Fusion42 review
A critical SSRF vulnerability (CVE-2026-64849) in MLflow allows unauthenticated attackers to steal cloud credentials by accessing internal cloud metadata endpoints, enabling full cloud account compromise. The vulnerability affects all MLflow versions before 3.15.0 and is actively exploited by cybercriminals, with urgent remediation mandated by CISA.
This Wire brief sits within Fusion42's coverage of AI Infrastructure and Security Infrastructure.
◆ ◆ The Wire takeaway
Your MLflow deployments just became a direct gateway to cloud theft and takeover. Patch or isolate these servers immediately or risk attackers turning your cloud into their own ransomware factory.
◆ Coverage
1 source · 20 Aug 2026
◆ Related on Wire
◆ Topics