< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-08-18T23:14:05+05:30

MLflow SSRF Vulnerability Exploited for Cloud Credential Theft

Attackers are exploiting a critical SSRF vulnerability in MLflow (CVE-2026-64849) to access cloud metadata services and steal credentials, while another vulnerability in FUXA (CVE-2026-25895) enables remote code execution through path traversal.

Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operational technology (OT) and industrial automation, are witnessing malicious scanning and exploitation efforts.

According to independent reports from watchTowr and VulnCheck, the vulnerabilities in question are as follows -

Read original article

*** END OF TRANSMISSION ***