Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets
Reported exploitedMLflowFUXAOur summary
Active exploitation has been observed against two distinct open-source platforms: MLflow, an AI lifecycle tool, and FUXA, a web-based SCADA/HMI solution for industrial automation. Threat actors are leveraging CVE-2026-64849 in MLflow versions prior to 3.15.0 to execute unauthenticated Server-Side Request Forgery attacks, allowing them to proxy requests to internal cloud metadata endpoints and exfiltrate sensitive credentials. Concurrently, vulnerabilities identified as CVE-2026-25895 in FUXA versions up to 1.2.9 are being scanned by attackers seeking to perform path traversal operations that could lead to remote code execution by overwriting critical system files.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.