HomeSecurityNew waves of attacks on MLflow and FUXA – Critical vulnerabilities targeted

New waves of attacks on MLflow and FUXA – Critical vulnerabilities targeted

Two particularly serious vulnerabilities in software used in artificial intelligence and industrial automation environments have now moved from theoretical threat to active targeting. The attacks involve MLflow, a popular open-source platform for managing machine learning applications, and FUXA, a web-based SCADA/HMI system used in operational technology and industrial automation infrastructures.

Article Image: Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets

Researchers at watchTowr and VulnCheck have identified malicious scans that look for exposed installations, increasing pressure on organizations that have not implemented the necessary security updates.

Critical SSRF vulnerability in MLflow

The first and most serious case concerns CVE-2026-64849, which has a CVSS score of 9.3. It is a Server-Side Request Forgery (SSRF), which does not require prior identification of the attacker.

See also: CVE-2026-58231: Critical SAP Commerce Cloud vulnerability being exploited

The issue is located in the operation of Model Registry webhooks and could allow an attacker with access to the MLflow tracking server to forward requests to arbitrary internal endpoints . In this way, the attacker could attempt to communicate with services that are normally not accessible from the internet, including cloud metadata services.

This feature is particularly dangerous in cloud environments, as such services may contain temporary credentials, tokens, or other secrets that can be exploited for further infiltration of the infrastructure.

CVE -2026-64849 affects versions of MLflow prior to 3.15.0 and, according to watchTowr, attackers began looking for exposed systems just hours after the CVE was released on August 17, 2026.

The redirect that can open the door

Of particular interest is the way in which this particular flaw is exploited. According to watchTowr research, the vulnerability is related to the handling of web redirects and can bypass previous protection efforts.

See also: GitLab RCE PoC: Exploit in self-managed GitLab via Jupyter notebook diff (Oj)

Honeypot telemetry shows that malicious actors are seeking out MLflow installations that are accessible over the internet, targeting services hosted on cloud infrastructures. The potential for stealing credentials and other secrets makes the vulnerability particularly concerning for organizations using MLflow in production environments.

Even more serious danger in FUXA

The second incident concerns CVE-2026-25895 in FUXA, with a CVSS score of 9.5. The vulnerability combines a lack of authentication for a critical function with path traversal and could allow a remote, unidentified attacker to write arbitrary files to the system.

The consequence is potentially extremely serious, as the ability to write files can lead to remote code execution (RCE) under certain circumstances. The issue affects FUXA versions up to and including 1.2.9.

The scans have already begun

VulnCheck detected malicious activity targeting this particular flaw since August 18. One IP address reportedly performed an extensive scan of the internet looking for vulnerable FUXA installations.

Although approximately 60 publicly exposed FUXA installations, no confirmed RCE payloads have been observed so far. However, researchers have identified requests that attempt to replace the main.js file with data via path traversal, indicating that the vulnerability is already being actively tested.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

New waves of attacks on MLflow and FUXA – Critical vulnerabilities targeted

FUXA has been targeted again

The picture becomes even more worrying when considering that FUXA has faced other active exploitation attempts. Vulnerabilities CVE-2026-25939 and CVE-2023-33831 have also been the subject of malicious activity, with the latter showing attacks as early as November 2025.

See also: Ill Bloom: Vulnerability allowed $3.1 million to be stolen from crypto wallets

What should organizations do?

Enterprises using MLflow or FUXA should address these vulnerabilities as a top priority. Installing available patches is the first step, but it is not enough on its own.

A parallel review of audit logs, search for suspicious requests and outbound connections , as well as checking for possible exposure of credentials or cloud secrets is required . In FUXA, limiting access from the internet is also of particular importance, as an exposed SCADA/HMI system can be a critical entry point in industrial environments.

The two cases confirm a now familiar pattern in cybersecurity: when a critical vulnerability is disclosed, the time frame between disclosure and the first malicious scans can be extremely short. For businesses, speed of update, limited service exposure, and continuous monitoring remain key defense factors.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS