Attackers Exploit MLflow SSRF to Steal Cloud Credentials — SkimNews

SkimNews Take
The race between disclosure and exploitation has compressed to hours, meaning ML/AI platforms now serve as fresh SSRF gateways to cloud metadata—turning any exposed instance into an automatic credential-harvesting probe.
Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- CVE-2026-64849 is an unauthenticated SSRF vulnerability (CVSS 9.3) in MLflow affecting versions below 3.15.0, allowing attackers who can reach the Tracking Server to issue HTTP requests to internal cloud metadata endpoints and extract sensitive data.
- watchTowr detected indiscriminate scanning for exposed MLflow instances within hours of the CVE being assigned on August 17, 2026, with attackers actively exfiltrating cloud credentials and secrets, per the firm's honeypot telemetry.
- The MLflow flaw bypasses prior fixes by exploiting the platform's model-registry webhooks to proxy requests through the affected system and abusing how it handles web redirects, according to watchTowr principal threat intelligence specialist Yordan Ganchev.
- CVE-2026-25895 is a missing-authentication and path traversal vulnerability (CVSS 9.5) in FUXA affecting versions up to 1.2.9, enabling unauthenticated remote attackers to write arbitrary files to the server filesystem and achieve remote code execution.
- VulnCheck identified a single IP broadly scanning for vulnerable FUXA instances starting August 18, 2026, with roughly 60 FUXA installations exposed to the public internet.
- Current FUXA attacks are overwriting main.js with junk data via the path traversal but have not yet dropped RCE payloads, per VulnCheck VP of research Caitlin Condon; two earlier FUXA CVEs (CVE-2026-25939 and CVE-2023-33831) have also seen active exploitation.
Why it matters: Organizations running cloud-hosted MLflow face immediate credential-theft risk since attackers weaponized the SSRF within hours of disclosure, while the roughly 60 internet-exposed FUXA installations—many in OT environments—represent potential pivot points for industrial disruption if scanning escalates to RCE.
Ask SkimNews




