DEV Community

Cover image for Attackers Exploit a Critical MLflow Vulnerability
BeyondMachines for BeyondMachines

Posted on Originally published at beyondmachines.net

Attackers Exploit a Critical MLflow Vulnerability

Summary

Attackers are actively exploiting a critical flaw in MLflow (CVE-2026-64849) to steal cloud credentials and gain remote code execution.

Take Action:

If you run MLflow, update it to version 3.15.0 or later ASAP, and make sure the server is not reachable from the internet. Then check your audit logs for any odd requests to cloud metadata services. If you see any (or aren't sure), rotate your cloud credentials and keys as a precaution.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)