Affected Systems

MLflow open-source AI engineering platform, all versions prior to 3.15.0. Default MLflow Tracking Server deployments without authentication are vulnerable. Affects organizations running MLflow for LLM and AI agent development, particularly those with publicly exposed instances.

Exploitation Status

Active exploitation confirmed. CISA added CVE-2026-64849 to KEV catalog. watchTowr reports attackers began scanning for vulnerable MLflow systems within hours of CVE assignment and are actively exfiltrating cloud credentials and secrets via cloud metadata services (e.g., AWS IMDS).

Business Impact

Unauthenticated attackers can exploit DNS-rebinding SSRF bypass to force MLflow servers to issue HTTP requests to internal services, cloud metadata endpoints, and loopback addresses. Successful exploitation enables theft of AWS IAM credentials, access to internal admin services, and internal network reconnaissance. Low complexity attack requiring no privileges. Federal agencies under BOD 26-04 must patch within two weeks; private sector should treat as urgent given active exploitation and credential theft risk.

Urgency

đź”´ Immediate

Recommended Actions

  • Immediately upgrade all MLflow instances to version 3.15.0 or later
  • Identify and prioritize patching publicly exposed MLflow Tracking Server deployments, especially those running default configurations without authentication
  • Review MLflow audit logs and web server access logs for suspicious POST requests to /api/2.0/mlflow/webhooks/*/test endpoint indicating reconnaissance or exploitation attempts
  • Check cloud provider audit logs (AWS CloudTrail, Azure Activity Log, GCP Cloud Audit Logs) for unauthorized access to instance metadata services (e.g., AWS IMDS at 169.254.169.254) originating from MLflow server IPs
  • Rotate cloud IAM credentials and secrets that may have been exposed on systems running vulnerable MLflow versions, particularly if instances were internet-accessible

---

# Geopolitical Context

Geopolitical Context

The active exploitation of CVE-2026-64849 in MLflow—a widely deployed open-source AI engineering platform—reflects the growing strategic importance of artificial intelligence infrastructure as a target for cyber operations. With over 30 million monthly downloads and adoption across thousands of organizations, MLflow represents critical supply chain infrastructure in the AI development ecosystem. The vulnerability's capacity to expose cloud credentials (including AWS IAM tokens) and internal network configurations positions it as a high-value target for both espionage-focused and pre-positioning operations. CISA's rapid inclusion of this flaw in its Known Exploited Vulnerabilities catalog and invocation of Binding Operational Directive 26-04 signals U.S. government concern that federal AI development and deployment infrastructure may be at risk. The exploitation timeline—with scanning activity beginning within hours of CVE assignment—is consistent with sophisticated threat actors monitoring vulnerability disclosures for immediate operational advantage. This incident underscores the dual challenge facing governments: securing emerging AI technologies while maintaining competitive advantage in a domain increasingly central to economic and military power.

State Actor Alignment

No specific state actor attribution has been disclosed by CISA or other U.S. government sources. The rapid exploitation timeline and targeting of government systems is consistent with the operational patterns of advanced persistent threat (APT) groups historically linked to nation-state intelligence services, though commercial cybercriminal actors also possess the capability to exploit SSRF vulnerabilities for credential theft and cloud environment access. The targeting of federal agencies and the vulnerability's utility for accessing cloud metadata services suggests potential intelligence collection objectives, though financial motivations cannot be excluded. CISA's directive mandates remediation within two weeks for Federal Civilian Executive Branch agencies, indicating assessment of ongoing risk to U.S. government operations. No sanctions, formal attribution statements, or diplomatic responses have been announced in connection with this exploitation activity.

Business Impacty pro region

The exploitation of MLflow carries implications beyond U.S. federal networks, given the platform's global adoption across government, academic, and commercial AI development programs. European institutions investing heavily in sovereign AI capabilities—particularly those leveraging open-source platforms to reduce dependency on proprietary U.S. or Chinese solutions—face similar exposure if running vulnerable MLflow instances. The vulnerability's capacity to exfiltrate cloud credentials threatens multi-cloud and hybrid infrastructure strategies common in European digital sovereignty initiatives. For allied intelligence-sharing frameworks such as Five Eyes, the compromise of AI development infrastructure could enable adversaries to access training data, model architectures, or operational deployment plans for AI-enabled defense and intelligence applications. Developing nations adopting MLflow through international development programs or academic partnerships may lack the monitoring and incident response capacity to detect exploitation, creating potential blind spots in the global AI supply chain. The incident may accelerate calls within the EU and other jurisdictions for mandatory security standards in AI development tooling and heightened scrutiny of open-source AI infrastructure dependencies.

Forecast

If exploitation continues at scale, additional government agencies and private sector organizations in allied nations are likely to discover compromised MLflow instances in coming weeks, potentially revealing broader campaign scope. If cloud credentials obtained through this vulnerability are weaponized in follow-on operations, affected organizations may experience data exfiltration, lateral movement into production AI systems, or manipulation of training datasets and model registries. Should attribution emerge linking exploitation to a specific state actor, the incident may prompt coordinated diplomatic responses or expanded export controls on AI development technologies, particularly if targeting extends to defense or critical infrastructure sectors. If the vulnerability is found to have been exploited prior to public disclosure, organizations may face extended forensic investigations to determine the scope of historical compromise. Conversely, if patching rates among high-value targets prove rapid and comprehensive, exploitation activity may shift toward less-secured commercial and academic MLflow deployments, potentially broadening the victim set but reducing immediate strategic impact. The incident is likely to inform ongoing policy debates regarding security requirements for AI development platforms and may accelerate adoption of zero-trust architectures for AI engineering environments.