[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fG8qaR78wToilxAG6iqq2BRAhs4WBTQUEqq045VG-IF4":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":50},"6e26c2a9-26fa-47a7-972e-5f8c4e26ea91","mlflow-ssrf-flaw-actively-exploited-to-steal-cloud-credentials","98834731-df72-411e-822c-5c313b2b9385","MLflow SSRF Flaw Actively Exploited to Steal Cloud Credentials","A critical Server-Side Request Forgery (SSRF) vulnerability in MLflow's unauthenticated webhooks API allowed attackers to pivot through the ML platform to extract cloud credentials and secrets without any authentication required. The root failure is twofold: a sensitive API endpoint was left exposed without authentication controls, and organizations failed to apply patches before active exploitation began. This matters because MLflow instances are commonly deployed in cloud environments with broad IAM permissions, meaning credential theft can rapidly escalate to full cloud account compromise. CISA's addition of this CVE to the Known Exploited Vulnerabilities catalog signals that this is not a theoretical risk — real-world attacks are already underway.","**Immediate actions:**\n- Upgrade all MLflow instances to version 3.15.0 or later before the CISA-mandated two-week federal deadline.\n- Restrict or firewall the model-registry webhooks API endpoint to trusted internal networks only until patching is complete.\n- Rotate all cloud credentials and secrets accessible from affected MLflow instances as a precautionary measure.\n\n**Long-term improvements:**\n- Enforce authentication and authorization on all MLflow API endpoints, including webhooks, as a baseline configuration standard.\n- Maintain a continuously updated inventory of all ML\u002FAI tooling deployed in cloud environments and include them in your vulnerability management program.\n- Apply least-privilege IAM policies to MLflow service accounts to limit the blast radius of any future credential exposure.\n\n**Detection measures:**\n- Monitor MLflow webhook API logs for anomalous outbound requests indicative of SSRF exploitation attempts.\n- Configure cloud provider alerts (e.g., AWS CloudTrail, Azure Monitor) to flag unusual credential usage or metadata service access originating from MLflow hosts.\n- Integrate CISA KEV catalog feeds into your vulnerability prioritization workflow to ensure critical CVEs trigger immediate response procedures.",[12,13,14,15,16,17,18,19,20,21,22,23],"CIS Control 7 – Continuous Vulnerability Management","CIS Control 4 – Secure Configuration of Enterprise Assets","CIS Control 6 – Access Control Management","NIST SP 800-53 SI-2 (Flaw Remediation)","NIST SP 800-53 AC-3 (Access Enforcement)","NIST SP 800-53 IA-9 (Service Identification and Authentication)","NIST SP 800-53 SC-7 (Boundary Protection)","NIST CSF ID.RA-1 (Asset Vulnerabilities Identified)","NIST CSF RS.MI-3 (Newly Identified Vulnerabilities Mitigated)","CISA BOD 22-01 – Reducing the Significant Risk of Known Exploited Vulnerabilities","MITRE ATT&CK T1552.005 – Cloud Instance Metadata API","MITRE ATT&CK T1190 – Exploit Public-Facing Application","published","2026-08-20T14:21:42.135955+00:00","2026-08-20T14:21:42.057+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fwww.securityweek.com\u002Fmlflow-vulnerability-exploited-for-cloud-credential-theft\u002F","mlflow-vulnerability-exploited-for-cloud-credential-theft-b437cb","MLflow Vulnerability Exploited for Cloud Credential Theft",[32,38,44],{"id":33,"name":34,"slug":35,"description":36,"color":37},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":39,"name":40,"slug":41,"description":42,"color":43},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":45,"name":46,"slug":47,"description":48,"color":49},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[51],{"id":52,"date":53,"edition":54,"title":55,"audio_url":56},"9c98511f-6932-4b1f-9b66-ddf17c4b655f","2026-08-20","afternoon","ThreatNoir Afternoon Brief — August 20","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-08-20\u002Fthreatnoir-afternoon-brief-2026-08-20.mp3"]