← Back

Wire · opportunities

Active Exploitation of MLflow SSRF Vulnerability (CVE-2026-64849) Enables Cloud ...

Published

20 August 2026

Topic

opportunities

Sectors

AI InfrastructureSecurity Infrastructure

Source

Read at rescana.com

Verified

Fusion42 · 21 August 2026 · Fusion42 review

A critical SSRF vulnerability (CVE-2026-64849) in MLflow allows unauthenticated attackers to steal cloud credentials by accessing internal cloud metadata endpoints, enabling full cloud account compromise. The vulnerability affects all MLflow versions before 3.15.0 and is actively exploited by cybercriminals, with urgent remediation mandated by CISA.

This Wire brief sits within Fusion42's coverage of AI Infrastructure and Security Infrastructure.

◆ The Wire takeaway

Your MLflow deployments just became a direct gateway to cloud theft and takeover. Patch or isolate these servers immediately or risk attackers turning your cloud into their own ransomware factory.

Coverage

1 source · 20 Aug 2026

Related on Wire

Topics

AI InfrastructureSecurity Infrastructuressrfmlflowcloud-securitycredential-theftcybersecuritycisa