THREAT OPS › Threat News › MLflow Bug Actively Exploited to Steal Credentials
MLflow Bug Actively Exploited to Steal Credentials
<p class="wp-block-paragraph">Security researchers have identified a critical vulnerability in MLflow that exposes default tracking server installations to unauthenticated Server-Side Request Forgery (SSRF) and attackers are already exploiting it.</p>
<p class="wp-block-paragraph">This flaw allows remote, unauthenticated attackers to read sensitive data from internal network services or cloud m
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-64849cve
- http://169.254.169.254/…url
- http://127.0.0.1:…url