Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets

Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets
Attackers are actively scanning and exploiting critical flaws in MLflow and FUXA, with MLflow abuse targeting cloud metadata services to steal credentials and secrets. FUXA is also seeing malicious internet-wide scanning against a path traversal issue that could let an attacker overwrite files and potentially achieve remote code execution. #MLflow #FUXA #CVE-2026-64849 #CVE-2026-25895

Keypoints

  • MLflow CVE-2026-64849 is an unauthenticated SSRF flaw affecting versions before 3.15.0.
  • Attackers are using the MLflow flaw to reach cloud metadata services and extract secrets.
  • FUXA CVE-2026-25895 is a critical path traversal and authentication bypass issue affecting versions 1.2.9 and earlier.
  • Malicious scanning for vulnerable FUXA instances began shortly after disclosure.
  • Other FUXA flaws, including CVE-2026-25939 and CVE-2023-33831, have also seen active exploitation.

Read More: https://thehackernews.com/2026/08/attackers-exploit-mlflow-ssrf-flaw-to.html