Citrix and MLflow Flaws Face Active Exploitation
Citrix NetScaler appliances are widely used to manage application traffic and remote access, making vulnerabilities in the products a potentially serious entry point into corporate networks. MLflow, an open-source platform for managing machine-learning and AI lifecycles, also holds privileged connections to cloud infrastructure. Security flaws in either system can expose sensitive environments, enable remote code execution or put cloud credentials at risk.
An Aug. 19 cybersecurity roundup said a high-risk Citrix NetScaler vulnerability was being actively exploited and carried a remote-code-execution threat. MLflow was also targeted through a server-side request forgery, or SSRF, weakness that could allow attackers to steal cloud credentials. GitLab and Apple issued emergency security updates as well, adding to calls for administrators and users to apply the latest patches promptly.
All Coverage
1 original reportsThe Backstory
The history behind this eventHackers Target Critical MLflow Flaw in Cloud Credential Attacks
MLflow, an open-source platform for tracking experiments and managing machine-learning models through deployment, is often connected to sensitive corporate cloud infrastructure. The server-side request forgery flaw, designated CVE-2026-64849, carries a CVSS severity score of 9.3. Successful exploitation could allow an unauthenticated attacker to make requests through a vulnerable MLflow server, probe internal services and reach cloud metadata endpoints that may expose credentials or other confidential information.
Security firm watchTowr said it detected large-scale scanning within hours of the vulnerability’s public disclosure, signaling that attackers were rapidly searching for internet-exposed MLflow instances. U.S. cybersecurity authorities later warned that the flaw was being actively exploited. The vulnerability has been fixed in MLflow version 3.15.0. Security teams are being urged to upgrade immediately and review server logs, cloud metadata access and credential activity for signs of compromise, particularly where MLflow deployments are publicly reachable.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →