CISA Warns of Exploited MLflow Vulnerability, Cybersecurity Risk

www.news4hackers.com-cisa-warns-of-exploited-mlflow-vulnerability-cybersecurity-risk-cisa-warns-of-exploited-mlflow-vulnerability-cybersecurity-risk

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert to federal entities regarding the active exploitation of a severe vulnerability in MLflow, an open-source platform for managing machine learning workflows.

The Vulnerability Explained

The flaw, tracked as CVE-2026-64849, enables unauthorized access to internal systems and cloud metadata through a server-side request forgery (SSRF) bypass in the platform’s outbound webhook functionality. The vulnerability affects MLflow versions prior to 3.15.0, which includes the default tracking server configuration using an unauthenticated SQLite backend.

Exploitation Mechanism

Attackers can exploit the synchronous POST /api/2.0/mlflow/webhooks/{id}/test endpoint to trigger HTTP requests to internal or cloud-hosted resources. This mechanism allows adversaries to retrieve sensitive data such as AWS Identity and Access Management (IAM) credentials, internal administrative interfaces, and network scan results from cloud instance metadata services.

CISA’s Response and Mandate

MLflow’s security team highlighted that the unauthenticated nature of the model-registry webhooks API creates a direct pathway for exploitation. By sending crafted requests, threat actors can bypass traditional network segmentation controls and access protected endpoints. This flaw has been confirmed in active cyberattacks, prompting CISA to classify it as a high-priority threat.

In response, CISA has updated its Known Exploited Vulnerabilities (KEV) catalog and mandated U.S. Federal Civilian Executive Branch (FCEB) agencies to remediate affected MLflow instances within 14 days. The directive aligns with Binding Operational Directive 26-04, which requires immediate patching for vulnerabilities that meet specific criteria, including public exposure, automation potential for large-scale attacks, and the ability to grant system control.

Broader Threat Landscape

While the mandate applies exclusively to federal agencies, CISA has urged all organizations to prioritize mitigation efforts. The agency emphasized that the flaw represents a common attack vector for malicious actors, with low complexity required for successful exploitation.

Separately, CISA reported that adversaries are also leveraging a critical remote code execution (RCE) vulnerability in the Windows Internet Key Exchange (IKE) Service Extensions component. This flaw, combined with the MLflow vulnerability, underscores a broader trend of attackers targeting infrastructure with minimal authentication requirements.

Data Insights and Recommendations

Data from The Blue Report 2026, which analyzed 338 million security simulations, reveals that 37% of attacker activities are blocked when valid credentials are compromised. This statistic highlights the importance of layered defense strategies and proactive patch management.

Organizations are advised to review their MLflow deployments, apply the latest security updates, and monitor for signs of unauthorized access to internal services. The vulnerability’s ease of exploitation and potential for data exfiltration make it a critical priority for cybersecurity teams.

“The flaw represents a common attack vector for malicious actors, with low complexity required for successful exploitation.”

Conclusion

CISA’s alert underscores the urgency of addressing critical vulnerabilities in widely used infrastructure. Organizations must act swiftly to mitigate risks, adopt robust security practices, and stay informed about emerging threats to protect their systems and data.

FAQs

What is MLflow, and why is it a target?

MLflow is an open-source platform for managing machine learning workflows. It is a target due to its widespread use and the presence of vulnerabilities like CVE-2026-64849, which allow unauthorized access to critical systems.

What steps should organizations take to mitigate this vulnerability?

Organizations should update MLflow to version 3.15.0 or later, review deployments for unauthenticated configurations, and monitor for signs of unauthorized access. Proactive patch management and layered security strategies are essential.

Is this vulnerability limited to federal agencies?

No. While CISA’s mandate applies to federal agencies, the vulnerability poses risks to all organizations using affected MLflow versions. CISA has urged all entities to prioritize mitigation.


Blog Image

About Author

en_USEnglish