Find notable cyber news and cases, enriched with sources, timelines, and signals.

MLflow and FUXA active exploitation wave

Exploitation Wave
First reported
Last updated
Happening score
H score 51
1 unique sources, 1 articles

Summary

Hide ▲

Active scanning and exploitation of MLflow and FUXA vulnerabilities is putting exposed systems at risk of cloud credential theft and remote code execution. CVE-2026-64849 in MLflow and CVE-2026-25895 in FUXA are both being targeted in the wild. The activity spans internet-wide probing of public instances and abuse attempts against reachable systems. The wave surfaced on August 17-18, 2026 and remains active.

Related Happenings

MLflow unauthenticated SSRF flaw (CVE-2026-64849)

Vulnerability
H score49 First: 18.08.2026 20:44 Last: 18.08.2026 20:44 Sources 1

How related: "Attackers are exploiting [CVE-2026-64849] to reach cloud metadata services directly, and exfiltrating cloud credentials and secrets,"

About this happening: CVE-2026-64849 in MLflow is being actively exploited against exposed Tracking Server deployments, creating immediate risk of cloud credential and secret theft. Attacke...

FUXA path traversal flaw (CVE-2026-25895, actively scanned)

Vulnerability
H score49 First: 18.08.2026 20:44 Last: 18.08.2026 20:44 Sources 1

How related: "The attacker request attempts to overwrite main.js with junk data via the CVE-2026-25895 path traversal," Caitlin Condon, vice president of research at VulnCheck, said in a LinkedIn post. "No RCE payloads dropped yet."

About this happening: Malicious scanning is targeting CVE-2026-25895 in FUXA <= 1.2.9, putting publicly exposed SCADA/HMI instances at risk of arbitrary file write and potential remote code...

Timeline

  1. 18.08.2026 20:44 1 articles · 3h ago

    Attackers target MLflow CVE-2026-64849 for cloud metadata access

    Exploitation Observed

    watchTowr says attackers are exploiting CVE-2026-64849 in MLflow to issue HTTP requests to arbitrary internal cloud metadata endpoints and extract sensitive data, with indiscriminate scanning for exposed MLflow instances appearing within hours of the CVE assignment on August 17, 2026.

    Show sources
  2. 18.08.2026 20:44 1 articles · 3h ago

    Malicious scanning targets FUXA CVE-2026-25895

    Exploitation Observed

    VulnCheck said malicious scanning aimed at CVE-2026-25895 in FUXA began on August 18, 2026, and observed request attempts to overwrite main.js with junk data through the path traversal flaw; the vulnerability can let an unauthenticated remote attacker write arbitrary files to the server file system and achieve remote code execution.

    Show sources
  3. 18.08.2026 20:44 2 articles · 3h ago

    watchTowr and VulnCheck disclose active exploitation of MLflow and FUXA flaws

    Initial Disclosure

    Independent reports from watchTowr and VulnCheck say MLflow CVE-2026-64849 and FUXA CVE-2026-25895 are witnessing malicious scanning and exploitation efforts, with MLflow attackers using SSRF to reach cloud metadata services and exfiltrate cloud credentials and secrets while FUXA probes attempt file overwrite via path traversal.

    Show sources