
CISA Warns of Active Exploitation of Critical MLflow Vulnerability by Threat Actors
cybersecurityAIvulnerabilityexploitMLflowsecurity
The Cybersecurity and Infrastructure Security Agency (CISA) issued a warning that threat actors are actively exploiting a critical vulnerability in MLflow, an open-source AI engineering platform. The agency added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to address it by a specified deadline. The vulnerability allows attackers to execute arbitrary code or gain unauthorized access to affected systems. No specific CVE ID, technical details, or exploitation timeline were provided in the notice. The warning targets U.S. federal agencies but implies broader risks for organizations using MLflow. Impact includes potential compromise of AI model development and deployment environments.