FUXA path traversal flaw (CVE-2026-25895, actively scanned)
Vulnerability
Summary
Hide ▲
Show ▼
Malicious scanning is targeting CVE-2026-25895 in FUXA <= 1.2.9, putting publicly exposed SCADA/HMI instances at risk of arbitrary file write and potential remote code execution. Observed requests attempt to overwrite main.js via path traversal, and the activity began on August 18, 2026. No RCE payloads have been seen yet, but the flaw is already being actively tested in the wild.
Related Happenings
Microsoft SharePoint CVE-2026-55040 + CVE-2026-63520 exploitation wave
Exploitation Wave
H score42
First: 26.08.2026 17:47
Last: 26.08.2026 17:47
Sources 1
About this happening:
Microsoft SharePoint servers exposed to the CVE-2026-55040 + CVE-2026-63520 chain are being probed for remote code execution, putting unpatched internet-facing systems...
Microsoft SharePoint CVE-2026-55040 + CVE-2026-63520 exploitation wave
Exploitation WaveAbout this happening: Microsoft SharePoint servers exposed to the CVE-2026-55040 + CVE-2026-63520 chain are being probed for remote code execution, putting unpatched internet-facing systems...
MLflow and FUXA active exploitation wave
Exploitation Wave
H score46
First: 18.08.2026 20:44
Last: 18.08.2026 20:44
Sources 1
How related:
Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operational technology (OT) and industrial automation, are witnessing malicious scanning and exploitation efforts.
About this happening:
Active scanning and exploitation of MLflow and FUXA vulnerabilities is putting exposed systems at risk of cloud credential theft and remote code execution. CVE-2...
MLflow and FUXA active exploitation wave
Exploitation WaveHow related: Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operational technology (OT) and industrial automation, are witnessing malicious scanning and exploitation efforts.
About this happening: Active scanning and exploitation of MLflow and FUXA vulnerabilities is putting exposed systems at risk of cloud credential theft and remote code execution. CVE-2...
Latest development: 20.08.2026 14:06
CISA added CVE-2026-64849 to its catalog of flaws exploited in the wild and ordered U.S. Federal Civilian Executive Branch agencies to secure MLflow instances within two weeks under Binding Operational Directive 26-04. The vulnerability is a critical DNS-rebinding server-side request forgery bypass in MLflow's outbound webhook delivery and can let an unauthenticated attacker reach internal services or cloud metadata endpoints on unpatched instances.
RondoDox persistent IoT and web app botnet campaign
Campaign
H score51
First: 01.01.2026 11:19
Last: 01.01.2026 11:19
Sources 1
Impact high
About this happening:
RondoDox ran a nine-month campaign against IoT devices and web applications to expand botnet enrollment. The operation began in March-April 2025 with initial r...
RondoDox persistent IoT and web app botnet campaign
CampaignAbout this happening: RondoDox ran a nine-month campaign against IoT devices and web applications to expand botnet enrollment. The operation began in March-April 2025 with initial r...
Timeline
-
18.08.2026 20:44 2 articles · 13d ago
Malicious scanning targets FUXA CVE-2026-25895
Detection Ioc UpdateVulnCheck detected malicious scanning against FUXA CVE-2026-25895 starting August 18, 2026, with a single IP broadly probing exposed FUXA instances and sending requests that attempt to overwrite main.js via path traversal. The flaw affects FUXA versions <= 1.2.9 and can let an unauthenticated remote attacker write arbitrary files to the server file system and potentially achieve remote code execution, although no RCE payloads had been dropped yet.
Show sources
- Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets — thehackernews.com — 18.08.2026 20:44
- Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets — thehackernews.com — 18.08.2026 20:44