// Alert

AWS threat report

// AWSCRITICAL

A critical SSRF vulnerability (CVE-2026-64849) in MLflow is being actively exploited to steal cloud credentials from AWS, GCP, and Azure environments. Unauthenticated attackers craft malicious webhook payloads to force MLflow servers to access cloud metadata endpoints, exfiltrating sensitive credentials and tokens. Multiple organizations across technology, finance, healthcare, and government sectors have confirmed compromise. CISA has listed the vulnerability in its Known Exploited Vulnerabilities catalog. Remediation requires immediate upgrade to MLflow 3.15.0 and isolation of MLflow servers from public internet access.

// Get alerts for AWS