CVE Tools
Back to feed
Exploited in the wild MLflow ai-ml FUXA MLflow Project ics-ot-iot

Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets

The Hacker News·By The Hacker News··2 min read
CVE Tools coverage

Active exploitation has been observed against two distinct open-source platforms: MLflow, an AI lifecycle tool, and FUXA, a web-based SCADA/HMI solution for industrial automation. Threat actors are leveraging CVE-2026-64849 in MLflow versions prior to 3.15.0 to execute unauthenticated Server-Side Request Forgery attacks, allowing them to proxy requests to internal cloud metadata endpoints and exfiltrate sensitive credentials. Concurrently, vulnerabilities identified as CVE-2026-25895 in FUXA versions up to 1.2.9 are being scanned by attackers seeking to perform path traversal operations that could lead to remote code execution by overwriting critical system files.