A critical MLflow vulnerability is now under active exploitation, according to the US Cybersecurity and Infrastructure Security Agency. The flaw can let unauthenticated attackers access internal services and cloud metadata on vulnerable MLflow servers. Tracked as CVE-2026-64849, the issue affects MLflow’s outbound webhook delivery system. Attackers can exploit it through a DNS rebinding server-side request…