MLflow Vulnerability Exploited for Cloud Credential Theft
The critical-severity flaw allows attackers to send HTTP requests to internal endpoints and extract sensitive information. The post MLflow Vulnerability Exploited for Cloud Credential Theft appeared first on SecurityWeek.
Threat actors have been exploiting a recent MLflow vulnerability to steal sensitive information, including credentials and secrets.
An open source AI engineering platform, MLflow allows users to manage the end-to-end machine learning lifecycle and deploy AI agents, LLMs, and ML models in production. It has over 27,000 GitHub stars and more than 60 million monthly downloads.
Tracked as CVE-2026-64849 (CVSS score of 9.3), the exploited security defect is described as an unauthenticated server-side request forgery (SSRF) issue that allows attackers to send HTTP requests to internal endpoints.
Source: https://www.securityweek.com/mlflow-vulnerability-exploited-for-cloud-credential-theft/
Related breach coverage
- GitLab Vulnerability Exploited One Day After Disclosure2026-09-11
The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server. The post GitLab Vulnerability Exploited One Day After Disclosure appeared first on SecurityWeek.
- ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks2026-09-14
The flaw allows attackers to send files and execute them without authorization through an active remote session. The post ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks appeared first on SecurityWeek.
- Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs2026-08-31
Named KindaRails2Shell, the arbitrary file read flaw allows attackers to extract secrets and execute arbitrary code remotely. The post Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek.
- SAP Patches Critical Extended Passport Processing Vulnerability2026-09-08
Affecting the SAP kernel code, the flaw allows unauthenticated, remote attackers to run arbitrary commands, recover secrets, and modify data. The post SAP Patches Critical Extended Passport Processing Vulnerability appeared first on SecurityWeek.