MLflow Critical Flaw: Patch Now to Stop Credential Theft
Summary
Hackers are actively targeting a critical vulnerability in the AI engineering platform, MLflow. This flaw, identified as CVE-2026-64849, is an unauthenticated Server-Side Request Forgery bug. It affects all versions of MLflow before 3.15.0. Thousands of organizations, including Meta, Accenture, and Microsoft, use MLflow to build AI models. The vulnerability allows attackers to proxy requests through affected systems. They can then interact with internal services and potentially extract credentials and secrets from cloud-hosted MLflow systems. This bypasses previous fixes due to how it handles web redirects. The Cybersecurity and Infrastructure Security Agency has warned US federal agencies to address this issue. If exploited, an attacker could retrieve cloud credentials and enumerate the cloud environment. This could lead to the compromise of sensitive data, secrets, and storage. It's crucial for users to update to version 3.15.0 to fix this serious security risk.
This is an AI-generated audio summary. Always check the original source for complete reporting.