MLflow and FUXA active exploitation wave
Exploitation Wave
Summary
Hide ▲
Show ▼
Active scanning and exploitation of MLflow and FUXA vulnerabilities is putting exposed systems at risk of cloud credential theft and remote code execution. CVE-2026-64849 in MLflow and CVE-2026-25895 in FUXA are both being targeted in the wild. The activity spans internet-wide probing of public instances and abuse attempts against reachable systems. The wave surfaced on August 17-18, 2026 and remains active.
Related Happenings
MLflow unauthenticated SSRF flaw (CVE-2026-64849)
Vulnerability
H score49
First: 18.08.2026 20:44
Last: 18.08.2026 20:44
Sources 1
How related:
"Attackers are exploiting [CVE-2026-64849] to reach cloud metadata services directly, and exfiltrating cloud credentials and secrets,"
About this happening:
CVE-2026-64849 in MLflow is being actively exploited against exposed Tracking Server deployments, creating immediate risk of cloud credential and secret theft. Attacke...
MLflow unauthenticated SSRF flaw (CVE-2026-64849)
VulnerabilityHow related: "Attackers are exploiting [CVE-2026-64849] to reach cloud metadata services directly, and exfiltrating cloud credentials and secrets,"
About this happening: CVE-2026-64849 in MLflow is being actively exploited against exposed Tracking Server deployments, creating immediate risk of cloud credential and secret theft. Attacke...
FUXA path traversal flaw (CVE-2026-25895, actively scanned)
Vulnerability
H score49
First: 18.08.2026 20:44
Last: 18.08.2026 20:44
Sources 1
How related:
"The attacker request attempts to overwrite main.js with junk data via the CVE-2026-25895 path traversal," Caitlin Condon, vice president of research at VulnCheck, said in a LinkedIn post. "No RCE payloads dropped yet."
About this happening:
Malicious scanning is targeting CVE-2026-25895 in FUXA <= 1.2.9, putting publicly exposed SCADA/HMI instances at risk of arbitrary file write and potential remote code...
FUXA path traversal flaw (CVE-2026-25895, actively scanned)
VulnerabilityHow related: "The attacker request attempts to overwrite main.js with junk data via the CVE-2026-25895 path traversal," Caitlin Condon, vice president of research at VulnCheck, said in a LinkedIn post. "No RCE payloads dropped yet."
About this happening: Malicious scanning is targeting CVE-2026-25895 in FUXA <= 1.2.9, putting publicly exposed SCADA/HMI instances at risk of arbitrary file write and potential remote code...
Timeline
-
18.08.2026 20:44 1 articles · 3h ago
Attackers target MLflow CVE-2026-64849 for cloud metadata access
Exploitation ObservedwatchTowr says attackers are exploiting CVE-2026-64849 in MLflow to issue HTTP requests to arbitrary internal cloud metadata endpoints and extract sensitive data, with indiscriminate scanning for exposed MLflow instances appearing within hours of the CVE assignment on August 17, 2026.
Show sources
- Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets — thehackernews.com — 18.08.2026 20:44
-
18.08.2026 20:44 1 articles · 3h ago
Malicious scanning targets FUXA CVE-2026-25895
Exploitation ObservedVulnCheck said malicious scanning aimed at CVE-2026-25895 in FUXA began on August 18, 2026, and observed request attempts to overwrite main.js with junk data through the path traversal flaw; the vulnerability can let an unauthenticated remote attacker write arbitrary files to the server file system and achieve remote code execution.
Show sources
- Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets — thehackernews.com — 18.08.2026 20:44
-
18.08.2026 20:44 2 articles · 3h ago
watchTowr and VulnCheck disclose active exploitation of MLflow and FUXA flaws
Initial DisclosureIndependent reports from watchTowr and VulnCheck say MLflow CVE-2026-64849 and FUXA CVE-2026-25895 are witnessing malicious scanning and exploitation efforts, with MLflow attackers using SSRF to reach cloud metadata services and exfiltrate cloud credentials and secrets while FUXA probes attempt file overwrite via path traversal.
Show sources
- Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets — thehackernews.com — 18.08.2026 20:44
- Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets — thehackernews.com — 18.08.2026 20:44