Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Exploit MLflow SSRF Flaw in Active Attacks

Hackers Exploit MLflow SSRF Flaw in Active Attacks

Posted on August 18, 2026 By CWS

Threat actors are currently targeting a severe server-side request forgery (SSRF) vulnerability in the popular open-source platform, MLflow. Widely used for tracking experiments and deploying models by data engineering and machine learning teams, this vulnerability poses a significant risk. Identified as CVE-2026-64849, it has received a critical CVSS score of 9.3, affecting all versions of MLflow prior to 3.15.0.

Immediate Exploitation Post-Disclosure

According to watchTowr Intel, adversaries began exploiting internet-exposed MLflow instances within hours of the flaw’s public disclosure. Utilizing their global Attacker Eye honeypot network, watchTowr detected attempts to harvest cloud credentials and sensitive tokens from these systems. The flaw stems from a default MLflow Tracking Server setup that lacks mandatory authentication, relying on a local SQLite backend and exposing critical webhooks APIs to untrusted network traffic.

Technical Details of the Vulnerability

The vulnerability lies in an unauthenticated POST request to the endpoint /api/2.0/mlflow/webhooks/{id}/test, which reflects the full upstream HTTP status code and response body. This reflection turns a standard request-forgery into a high-impact exploit, allowing attackers to access sensitive information. Although MLflow version 3.10.0 introduced a validation function to block private and cloud metadata addresses, it only evaluates the initial destination. The delivery handler in mlflow/webhooks/delivery.py, however, follows HTTP redirects without re-validating the new address.

Exploitation Across Cloud Providers

On major cloud platforms such as AWS, Azure, and Google Cloud, the reflected responses allow attackers to extract temporary IAM credentials, OAuth tokens, and environment configurations. The vulnerability also enables querying of internal microservices and loopback consoles. The rapid exploitation of this flaw reflects a trend where automated scanners quickly weaponize such vulnerabilities against exposed infrastructure.

Mitigation Measures and Future Outlook

MLflow maintainers have fixed these vulnerabilities in version 3.15.0. Organizations using internet-facing or shared Tracking Servers are advised to upgrade immediately. Since applying patches does not revoke already-exfiltrated credentials, security teams must audit access logs, rotate all cloud IAM keys, and enforce network egress filtering. Implementing identity-aware proxies can further isolate internal tracking portals from public networks, enhancing security against future threats.

Cyber Security News Tags:cloud security, CVE-2026-64849, Cybersecurity, data security, Exploitation, machine learning, MLflow, patch management, SSRF, Vulnerability

Post navigation

Previous Post: Microsoft Copilot Vulnerabilities Risk Data Exposure
Next Post: Critical MLflow and FUXA Vulnerabilities Exploited by Attackers

Related Posts

DHS Asks OpenAI To Share Information on ChatGPT Prompts Used By Users DHS Asks OpenAI To Share Information on ChatGPT Prompts Used By Users Cyber Security News
Hackers Registered 18,000 Holiday-Themed Domains Targeting ‘Christmas,’ ‘Black Friday,’ and ‘Flash Sale’ Hackers Registered 18,000 Holiday-Themed Domains Targeting ‘Christmas,’ ‘Black Friday,’ and ‘Flash Sale’ Cyber Security News
Hackers use Fake Cloudflare Verification Screen to Trick Users into Executing Malware Hackers use Fake Cloudflare Verification Screen to Trick Users into Executing Malware Cyber Security News
Microsoft’s Copilot Disclaimer Sparks Security Debate Microsoft’s Copilot Disclaimer Sparks Security Debate Cyber Security News
H2Miner Attacking Linux, Windows, and Containers to Mine Monero H2Miner Attacking Linux, Windows, and Containers to Mine Monero Cyber Security News
Upcoming DMARC Enhancements Discussed by Email Experts Upcoming DMARC Enhancements Discussed by Email Experts Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Urgent Update: Dell Container Storage Security Vulnerabilities
  • Urgent Update: GitLab AI Gateway Vulnerability
  • Debian Updates 1,313 Vulnerabilities to Prevent Security Risks
  • Citrix NetScaler Reboot Issues Post-Patch
  • Session Cookie Flaw Risks Entra ID MFA Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Urgent Update: Dell Container Storage Security Vulnerabilities
  • Urgent Update: GitLab AI Gateway Vulnerability
  • Debian Updates 1,313 Vulnerabilities to Prevent Security Risks
  • Citrix NetScaler Reboot Issues Post-Patch
  • Session Cookie Flaw Risks Entra ID MFA Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark