VMTech
Discuss a project

MLflow SSRF Exploited as FUXA Systems Face Internet Scanning

MLflow SSRF Exploited as FUXA Systems Face Internet Scanning

Attackers are actively exploiting CVE-2026-64849, a critical server-side request forgery flaw in the open-source AI platform MLflow, to obtain cloud credentials and secrets. The vulnerability has a CVSS score of 9.3, affects MLflow versions earlier than 3.15.0, and can be abused without authentication by an attacker able to reach an MLflow Tracking Server.

Independent reporting from watchTowr indicates that malicious actors started indiscriminately scanning the internet for exposed MLflow instances within hours of the CVE being assigned on August 17, 2026. The activity is aimed at cloud-hosted deployments and internal services reachable through the affected server.

MLflow webhooks can proxy internal requests

The weakness lies in MLflow model-registry webhooks. It allows an attacker to proxy HTTP requests through a vulnerable MLflow system to arbitrary internal cloud metadata endpoints, potentially extracting sensitive information. Yordan Ganchev, principal threat intelligence specialist at watchTowr, said the bug bypasses prior fixes because of the way MLflow handles web redirects.

watchTowr's global honeypot telemetry shows attempts to target well-known internal IP addresses and services used by cloud environments for metadata access. Such services can expose credentials and secrets if an application can be induced to make requests to them.

The new exploitation activity sits alongside broader attention to vulnerabilities affecting AI-connected infrastructure, including AI agent incident activity and its coverage of incidents involving AI agents. For MLflow operators, the immediate concern is that a publicly reachable Tracking Server may serve as a path into services that should not be accessible from the internet.

FUXA vulnerability also attracts malicious scanning

VulnCheck separately detected scanning for CVE-2026-25895, a CVSS 9.5 vulnerability affecting the open-source FUXA web-based SCADA and HMI software for operational technology and industrial automation. The issue combines missing authentication for a critical function with path traversal, enabling an unauthenticated remote attacker to write arbitrary files to the server file system and potentially achieve remote code execution. FUXA versions 1.2.9 and earlier are affected.

Scanning began on August 18, 2026, and VulnCheck observed one IP address broadly probing the internet for vulnerable FUXA deployments. About 60 FUXA installations are exposed publicly. The observed request sought to overwrite main.js with junk data through the path traversal issue; VulnCheck had not seen remote-code-execution payloads delivered at the time of its report.

Priorities for exposed deployments

Organizations should prioritize patching exposed MLflow instances, review audit logs for indications of compromise, and determine whether sensitive credentials may have been exposed. Teams operating FUXA should identify internet-facing installations and apply available remediation for affected versions. The practical business implication is clear: externally reachable AI and OT management systems require urgent patching and credential review when active scanning or exploitation is reported.

#mlflow#cloudsecurity#vulnerability#otsecurity
Open analytics
On the site 0 views
min read 4 18.08.2026
Instagram

MLflow SSRF Exploited as FUXA Systems Face Internet Scanning

Open the post on Instagram ↗