CVE-2026-64849 — an unauthenticated SSRF in MLflow with a CVSS score of 9.3 — is already being abused to reach cloud metadata services and exfiltrate credentials, researchers say.
CVE-2026-64849: MLflow SSRF lets attackers reach cloud metadata endpoints
Independent reporting from watchTowr and VulnCheck identifies CVE-2026-64849 as an unauthenticated Server-Side Request Forgery (SSRF) affecting MLflow versions older than 3.15.0. The vulnerability carries a CVSS score of 9.3. According to watchTowr, attackers who can reach an MLflow Tracking Server can issue HTTP requests to arbitrary internal cloud metadata endpoints and extract sensitive data, including cloud credentials and secrets.
watchTowr reported that malicious actors began indiscriminately scanning for exposed MLflow instances within hours of the CVE being assigned on August 17, 2026, and that they are exploiting the flaw to reach cloud metadata services directly. The advisory urged organizations running MLflow to prioritize patching, review audit logs for signs of compromise, and check whether sensitive credentials have been exposed.
How attackers are abusing MLflow model-registry webhooks
"It allows an attacker to exploit a flaw in MLflow's model-registry webhooks to proxy requests through the affected system and interact with internal services," Yordan Ganchev, principal threat intelligence specialist at watchTowr, told The Hacker News. Ganchev added that the bug bypasses prior fixes because of how it handles web redirects.
watchTowr said its global honeypot telemetry shows attackers are abusing this vulnerability to target cloud-hosted MLflow systems and to attempt extraction of credentials and secrets from well-known internal IP addresses and services. The pattern described combines a publicly reachable Tracking Server with a webhook-proxying behavior that can be redirected toward internal cloud metadata endpoints.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadCVE-2026-25895: FUXA path traversal, missing authentication, and active scanning
VulnCheck reported active malicious scanning for CVE-2026-25895 beginning on August 18, 2026. The vulnerability, with a CVSS score of 9.5, affects FUXA versions up to and including 1.2.9 and combines a missing authentication for a critical function with a path traversal that can allow an unauthenticated remote attacker to write arbitrary files to the server filesystem and achieve remote code execution.
VulnCheck observed a single IP address broadly scanning the internet for vulnerable FUXA instances and noted that roughly 60 FUXA installations are exposed to the public internet. Caitlin Condon, vice president of research at VulnCheck, said on LinkedIn, "The attacker request attempts to overwrite main.js with junk data via the CVE-2026-25895 path traversal." At the time of the report, no remote-code-execution payloads had been dropped.
FUXA's recent vulnerability history and continued probing
VulnCheck highlighted that exploitation activity against FUXA is not new. Over the past year, two other vulnerabilities — CVE-2026-25939 and CVE-2023-33831 — have seen active exploitation attempts. Condon said activity related to CVE-2023-33831 dates "back to November 2025 and as recently as yesterday," underscoring sustained interest by attackers in exposed FUXA instances.
What this means for security teams, OT operators, and cloud admins
- Security teams and ML practitioners: Prioritize patching MLflow instances to 3.15.0 or later, monitor Tracking Server logs for unexpected webhook activity and outbound proxying, and audit credential usage for signs of exfiltration, as recommended by watchTowr.
- OT and industrial automation operators running FUXA: Identify public-facing FUXA installations (VulnCheck cites about 60 exposed) and apply updates beyond 1.2.9, check for unauthorized file writes such as corruption of main.js, and monitor for scanning activity from single IPs probing for the CVE-2026-25895 path traversal.
- Cloud administrators and credential custodians: Because MLflow exploitation is being used to reach cloud metadata services, review metadata access logs and credential issuance patterns for anomalous requests and rotate any credentials or secrets that may have been exposed.
The immediate pattern is clear: two high-severity, unauthenticated flaws—one targeting MLflow webhooks to proxy requests to internal cloud metadata, the other enabling unauthenticated path traversal and file writes in FUXA—are actively being scanned and probed in the wild. The research firms involved have tied activity to concrete indicators: fast scanning following the MLflow CVE assignment on August 17, 2026; honeypot telemetry showing attempts to extract cloud secrets; a single IP scanning for FUXA; and roughly 60 publicly exposed FUXA installs.
Organizations that host MLflow Tracking Servers or public FUXA instances face a narrow window to act: patch the affected software, comb logs for evidence of exploitation, and treat any exposed cloud credentials or overwritten files as compromised until proven otherwise.
Original reporting: https://thehackernews.com/2026/08/attackers-exploit-mlflow-ssrf-flaw-to.html




