Attackers Exploit MLflow SSRF to Steal Cloud Credentials

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- MLflow's CVE-2026-64849 (CVSS 9.3) is an unauthenticated SSRF flaw that lets attackers proxy requests through MLflow's model-registry webhooks to reach internal cloud metadata endpoints and exfiltrate credentials and secrets, affecting versions before 3.15.0.
- watchTowr detected indiscriminate scanning for exposed MLflow instances online within hours of the CVE's August 17, 2026 assignment, with global honeypot telemetry confirming attackers targeting cloud-hosted MLflow systems to extract credentials from internal IP addresses.
- FUXA's CVE-2026-25895 (CVSS 9.5) combines missing authentication with a path traversal flaw, allowing unauthenticated remote attackers to write arbitrary files to the server file system and achieve remote code execution on versions up to 1.2.9.
- VulnCheck observed malicious scanning for the FUXA flaw beginning August 18, 2026, with a single IP broadly scanning the internet across roughly 60 publicly exposed FUXA installations, though attackers have so far only overwritten main.js with junk data rather than dropping RCE payloads.
- Two other FUXA CVEs — CVE-2026-25939 and CVE-2023-33831 — have also seen active exploitation over the past year, with activity on the latter dating back to November 2025 and continuing through recent days, according to VulnCheck's Caitlin Condon.
- watchTowr's Yordan Ganchev noted that the MLflow SSRF bug bypasses prior fixes because of how it handles web redirects, making this a regression rather than a new attack class against the platform.
- Organizations running MLflow are urged to prioritize patching exposed systems, review audit logs for compromise indicators, and verify whether sensitive credentials have been exposed from cloud metadata services.
Why it matters: With scanning detected within hours of CVE publication and approximately 60 FUXA installations exposed publicly, organizations running either platform face immediate patching pressure. The MLflow SSRF specifically threatens AI/ML infrastructure by targeting cloud metadata services — the same attack surface that has historically yielded broad cloud access — while the FUXA path traversal puts operational technology environments one file-write away from full remote code execution.
Ask SkimNews




