importantSYS.SOURCE: The Hacker News• 2026-08-18T23:14:05+05:30
MLflow SSRF Vulnerability Exploited for Cloud Credential Theft
Attackers are exploiting a critical SSRF vulnerability in MLflow (CVE-2026-64849) to access cloud metadata services and steal credentials, while another vulnerability in FUXA (CVE-2026-25895) enables remote code execution through path traversal.
Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operational technology (OT) and industrial automation, are witnessing malicious scanning and exploitation efforts.
According to independent reports from watchTowr and VulnCheck, the vulnerabilities in question are as follows -
*** END OF TRANSMISSION ***