Researchers disclosed a critical (CVSS 9.3) unauthenticated server-side request forgery flaw in the model-registry webhooks API of the open-source MLflow machine-learning platform, tracked as CVE-2026-64849. Within hours of the CVE being assigned in August 2026, financially motivated attackers began mass-scanning the internet for exposed MLflow tracking servers and using the flaw to reach cloud metadata services, harvesting AWS IAM tokens, Google Cloud service account keys, and Azure Managed Identity credentials. The vulnerability was added to CISA’s Known Exploited Vulnerabilities catalog, with federal agencies ordered to patch within two weeks; all MLflow versions prior to 3.15.0 are affected.