Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Georgia Power, Alabama Power Data Breach Hits 400,000 Accounts

    October 7, 2026

    Crypto Long & Short: Zcash and the case for privacy in the age of AI

    October 7, 2026

    Scientists changed how zoo lions eat. Their wild side came out

    October 7, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Georgia Power, Alabama Power Data Breach Hits 400,000 Accounts
    • Crypto Long & Short: Zcash and the case for privacy in the age of AI
    • Scientists changed how zoo lions eat. Their wild side came out
    • International pledge to fund forest rights exceeds target, but direct funding remains low
    • Guest opinion: Wisconsin should tax data centers to fund child care
    • Your Right to Know: Contenders for governor weigh in on open government
    • Beware rightwing economic myths such as ‘maxing out the nation’s credit card’ | Economics
    • Canada suspends plans to expand assisted dying to people with mental illness
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, October 7
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    CISA warns of hackers exploiting critical MLflow vulnerability

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 20, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies that threat actors are now exploiting a critical MLflow vulnerability.

    MLflow is an open-source AI engineering platform for large language models (LLMs) and agents backed by the Linux Foundation, with over 30 million monthly downloads, used by thousands of organizations to debug, evaluate, optimize, and monitor AI applications.

    Tracked as CVE-2026-64849, this critical DNS-rebinding server-side request forgery (SSRF) bypass in MLflow’s outbound webhook delivery was patched in version 3.15.0 and can be used by attackers without privileges to remotely access internal services or cloud metadata configurations on unpatched instances.

    image

    “The default MLflow Tracking Server (mlflow server, no authentication, default SQLite backend) exposes the model-registry webhooks API unauthenticated, including a synchronous POST /api/2.0/mlflow/webhooks/{id}/test endpoint that returns the upstream response status and body to the caller,” MLflow’s security team says in a security advisory issued three weeks ago.

    “An unauthenticated attacker who can reach the tracking server makes the server issue HTTP requests to arbitrary internal/loopback/cloud-metadata endpoints and reads the responses via /test: cloud instance-metadata (e.g. AWS IMDS IAM credentials), internal-only admin services behind the network boundary, and internal port/host scanning.”

    Successful exploitation can allow threat actors to steal cloud credentials, such as AWS Identity and Access Management (IAM) credentials, in low-complexity attacks.

    Tagged as exploited in attacks

    On Wednesday, CISA added the vulnerability to its catalog of flaws exploited in the wild and ordered U.S. Federal Civilian Executive Branch (FCEB) agencies to secure their MLflow instances within two weeks as mandated by Binding Operational Directive 26-04.

    BOD 26-04 was issued in June, and it requires U.S. government agencies to prioritize patching if the vulnerable assets are publicly exposed online, if the security flaw was added to CISA’s KEV catalog, if exploitation can be automated for large-scale attacks, and if successful exploitation gives attackers partial or total control of a targeted system.

    While BOD 26-04 applies only to U.S. government agencies, CISA urged all network defenders to prioritize patching their systems against attacks targeting CVE-2026-64849.

    “This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise,” the cybersecurity agency warned. “Stakeholders are responsible for evaluating each asset’s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.”

    On Tuesday, CISA warned that hackers are now also abusing a critical-severity remote code execution (RCE) flaw in the Windows Internet Key Exchange (IKE) Service Extensions component.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    CISA critical exploiting hackers MLflow Vulnerability warns
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Georgia Power, Alabama Power Data Breach Hits 400,000 Accounts

    Labour could oversee worst parliament on record for living standards, study warns | UK cost of living crisis

    Microsoft Outlook to block MSIX attachments starting November

    The Sixth Voice of the CISO Data Shows Cyber Risk Has Moved Inside the Workflow

    Ransomware has a new target. Is your backup ready?

    Hackers exploit critical Atlassian flaw after public PoC release

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Georgia Power, Alabama Power Data Breach Hits 400,000 Accounts

    October 7, 2026

    Crypto Long & Short: Zcash and the case for privacy in the age of AI

    October 7, 2026

    Scientists changed how zoo lions eat. Their wild side came out

    October 7, 2026

    International pledge to fund forest rights exceeds target, but direct funding remains low

    October 7, 2026
    Latest Posts

    British national shot dead in Kashmir by Pakistani security forces | Kashmir

    August 10, 2026

    Climate change doubled likelihood of Canada’s extreme fire weather, study finds

    August 10, 2026

    Scientists say just 7 days of meditation can rewire your brain

    August 10, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Georgia Power, Alabama Power Data Breach Hits 400,000 Accounts

    October 7, 2026

    Crypto Long & Short: Zcash and the case for privacy in the age of AI

    October 7, 2026

    Scientists changed how zoo lions eat. Their wild side came out

    October 7, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.