Overview
- Security teams assigned the bug CVE-2026-64849 and MLflow fixed it in release 3.15.0, with all earlier versions confirmed vulnerable.
- Researchers and honeypots reported widespread scanning and in-the-wild exploitation that began within hours of the CVE being published.
- CISA added CVE-2026-64849 to its Known Exploited Vulnerabilities catalog and told federal civilian agencies on Wednesday to secure exposed MLflow instances within two weeks under Binding Operational Directive 26-04.
- Attackers abuse an unauthenticated webhook test endpoint to trigger redirects or DNS re-resolution so the tracking server will request and return responses from internal IPs or cloud metadata endpoints such as AWS IMDS.
- Defenders are urged to update to MLflow 3.15.0, restrict public access or add authentication, rotate any cloud credentials that could have been exposed, apply least-privilege roles, and block egress to link-local and management networks.