Close Menu
NCIJ Network NCIJ Network
    What's Hot

    The Pentagon Hopes to Speed Up ‘Kill Chain’ AI Buys With 5-Minute Videos

    October 7, 2026

    Microsoft Outlook to block MSIX attachments starting November

    October 7, 2026

    Bitcoin price has risen 84% since January 2024 while Treasury yields climbed

    October 7, 2026
    Facebook X (Twitter) Instagram
    Trending
    • The Pentagon Hopes to Speed Up ‘Kill Chain’ AI Buys With 5-Minute Videos
    • Microsoft Outlook to block MSIX attachments starting November
    • Bitcoin price has risen 84% since January 2024 while Treasury yields climbed
    • Taking antibiotics? Sugar may be making the damage worse
    • Maine’s Next Governor Will Walk a Tightrope Between Energy Affordability and Climate Action
    • Trump’s Red-Dye Diesel Plan Will Bring Little Relief
    • Ukraine Claws Back Land in the Donbas, Thwarting a Russian Push
    • Greens investigate party member behind Zionism motion
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, October 7
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    CISA warns of hackers exploiting critical MLflow vulnerability

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 20, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies that threat actors are now exploiting a critical MLflow vulnerability.

    MLflow is an open-source AI engineering platform for large language models (LLMs) and agents backed by the Linux Foundation, with over 30 million monthly downloads, used by thousands of organizations to debug, evaluate, optimize, and monitor AI applications.

    Tracked as CVE-2026-64849, this critical DNS-rebinding server-side request forgery (SSRF) bypass in MLflow’s outbound webhook delivery was patched in version 3.15.0 and can be used by attackers without privileges to remotely access internal services or cloud metadata configurations on unpatched instances.

    image

    “The default MLflow Tracking Server (mlflow server, no authentication, default SQLite backend) exposes the model-registry webhooks API unauthenticated, including a synchronous POST /api/2.0/mlflow/webhooks/{id}/test endpoint that returns the upstream response status and body to the caller,” MLflow’s security team says in a security advisory issued three weeks ago.

    “An unauthenticated attacker who can reach the tracking server makes the server issue HTTP requests to arbitrary internal/loopback/cloud-metadata endpoints and reads the responses via /test: cloud instance-metadata (e.g. AWS IMDS IAM credentials), internal-only admin services behind the network boundary, and internal port/host scanning.”

    Successful exploitation can allow threat actors to steal cloud credentials, such as AWS Identity and Access Management (IAM) credentials, in low-complexity attacks.

    Tagged as exploited in attacks

    On Wednesday, CISA added the vulnerability to its catalog of flaws exploited in the wild and ordered U.S. Federal Civilian Executive Branch (FCEB) agencies to secure their MLflow instances within two weeks as mandated by Binding Operational Directive 26-04.

    BOD 26-04 was issued in June, and it requires U.S. government agencies to prioritize patching if the vulnerable assets are publicly exposed online, if the security flaw was added to CISA’s KEV catalog, if exploitation can be automated for large-scale attacks, and if successful exploitation gives attackers partial or total control of a targeted system.

    While BOD 26-04 applies only to U.S. government agencies, CISA urged all network defenders to prioritize patching their systems against attacks targeting CVE-2026-64849.

    “This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise,” the cybersecurity agency warned. “Stakeholders are responsible for evaluating each asset’s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.”

    On Tuesday, CISA warned that hackers are now also abusing a critical-severity remote code execution (RCE) flaw in the Windows Internet Key Exchange (IKE) Service Extensions component.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    CISA critical exploiting hackers MLflow Vulnerability warns
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Microsoft Outlook to block MSIX attachments starting November

    The Sixth Voice of the CISO Data Shows Cyber Risk Has Moved Inside the Workflow

    Ransomware has a new target. Is your backup ready?

    Hackers exploit critical Atlassian flaw after public PoC release

    SonicWall warns of max severity SSRF flaw in SMA1000 gateways

    New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    The Pentagon Hopes to Speed Up ‘Kill Chain’ AI Buys With 5-Minute Videos

    October 7, 2026

    Microsoft Outlook to block MSIX attachments starting November

    October 7, 2026

    Bitcoin price has risen 84% since January 2024 while Treasury yields climbed

    October 7, 2026

    Taking antibiotics? Sugar may be making the damage worse

    October 7, 2026
    Latest Posts

    British national shot dead in Kashmir by Pakistani security forces | Kashmir

    August 10, 2026

    Climate change doubled likelihood of Canada’s extreme fire weather, study finds

    August 10, 2026

    Scientists say just 7 days of meditation can rewire your brain

    August 10, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    The Pentagon Hopes to Speed Up ‘Kill Chain’ AI Buys With 5-Minute Videos

    October 7, 2026

    Microsoft Outlook to block MSIX attachments starting November

    October 7, 2026

    Bitcoin price has risen 84% since January 2024 while Treasury yields climbed

    October 7, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.