PoC Discloses for CVE-2026-64849: watchTowr Sees Attacks on MLflow SSRF
A public PoC for CVE-2026-64849, an unauthenticated MLflow SSRF (CVSS 9.3), is now live. watchTowr reports exploitation attempts. Patch to 3.15.0.
Related Posts:
- CVE-2026-71290: Apache HttpClient Flaw Lets Attackers Intercept and Modify Traffic (CVSS 9.1)
- CVE-2026-75045: Unauthenticated Attacker Could Download YouTrack Database Backups
- GeoServer Unauthenticated SQL Injection (CVSS 9.8) Exploited in the Wild, PoC Public
The post PoC Discloses for CVE-2026-64849: watchTowr Sees Attacks on MLflow SSRF appeared first on Daily CyberSecurity.