Full research report
Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets
Executive assessment
Several CVEs affecting both MLflow (AI/ML platform) and FUXA (SCADA/OT tool) are confirmed with live exploitation efforts in progress. MLflow's SSRF enables unauthenticated requests to cloud metadata endpoints, a critical path to credential leakageβthis is being attacked rapidly after CVE release. FUXA path traversal and RCE flaws attracted scanning and practical PoC development, risking arbitrary code execution for exposed OT/SCADA systems. Multiple advisories, vendor patches, and actual exploit code are public. Defensive action should prioritise rapid patching, credential reviews, and perimeter reduction on affected services; uncertainties remain around attacker attribution and credential exposure extent.
What happened
In August 2026, critical vulnerabilities in MLflow and FUXA, two open-source platforms, were actively targeted. MLflow's SSRF flaw (CVE-2026-64849) allowed unauthenticated access to internal cloud metadata; observed exploitation followed public disclosure. FUXA experienced scanning and exploitation for path traversal (CVE-2026-25895) and RCE flaws (CVE-2023-33831), impacting SCADA/OT deployments.
Affected scope
MLflow versions prior to 3.15.0; FUXA versions up to and including 1.2.9; about 60 public FUXA installations noted as exposed. Targets include AI platform users (MLflow) and industrial OT/SCADA users (FUXA).
Technical assessment
MLflow's unauthenticated webhook test endpoint allowed proxying of requests to internal/cloud metadata services, enabling theft of credentials. FUXA's vulnerabilities involved unauthenticated path traversal and remote code execution risks via crafted HTTP POST requests.
Recommended defensive actions
- Immediately patch MLflow installations to 3.15.0 or later.
- Immediately update FUXA to version 1.2.10+ for CVE-2026-25895, and to 1.2.11+ for CVE-2026-25939.
- Review and audit cloud and MLflow/FUXA server logs for historical SSRF/exfiltration attempts.
- Restrict exposure of MLflow and FUXA interfaces from open internet; apply network ACLs where possible.
Uncertainties and evidence gaps
- Attribution of threat actors exploiting these flaws remains unclear.
- Extent of post-exploitation, compromised cloud credentials, or lateral movements is undetermined based on current public sources.
Vulnerability flow
Defender-oriented path reconstructed only from sourced report findings. Unknown stages are omitted.
Active exploitation of CVE-2026-64849 and CVE-2023-33831 is reported; malicious scanning for CVE-2026-25895 and CVE-2026-25939 is ongoing.
The investigation began with an untrusted news report linking active exploitation to recent MLflow and FUXA vulnerabilities. Cross-referencing supplied CVEs with authoritative advisories and NVD records, I confirmed exploitation timelines, affected versions, and mitigation actions. Independent confirmation was established via vendor advisories, committed fixes, and technical PoCs. Defensive recommendations were derived directly from changed versions and incident reports.
- What vulnerabilities are covered in the headline event?Reviewed The Hacker News story and extracted referenced CVEs and claimed exploit activity.thehackernews.com β
Reports live exploitation of MLflow SSRF and scanning for FUXA flaws.
why Established initial timeline and claims for verification.
- Is CVE-2026-64849 legitimate and what is its scope?Checked NVD record for CVE-2026-64849.nvd.nist.gov β
Confirmed MLflow SSRF in webhook test endpoint; fixed in 3.15.0.
why Confirmed authoritative scope, impact, and patch version.
- Is there a real MLflow vendor advisory and patch?Located vendor advisory and release notes.
Vendor details and remediation guidance for SSRF bug.
why Verifies fix mechanism and supporting source.
- Are FUXA vulnerabilities CVE-2026-25895 and CVE-2026-25939 confirmed and what are technical details?Checked NVD for CVE-2026-25895 and CVE-2026-25939.nvd.nist.gov β
Confirmed path traversal and authentication bypass; patched in 1.2.10/1.2.11.
why Validated affected versions and existing mitigation.
- Is there public exploit or PoC code?Followed NVD advisory for CVE-2023-33831 to confirm PoC.
Authenticated public exploit for old FUXA RCE.
why Indicates exploitation risk and PoC availability.
- Is activity confirmed by independent sources?Reviewed news post and referenced LinkedIn/public comments from watchTowr and VulnCheck.thehackernews.com β
Consistent reporting of live scanning and exploitation.
why Cross-verifies claims of ongoing exploitation and targets.
- What are concrete remediation actions?Analysed vendor patch advisories and NVD for upgrade paths.
Upgrade instructions and log review recommendations.
why Directs immediate defender actions based on authoritative guidance.
Research coverage
All 68 registered source leaves were evaluated for this run: 61 completed, 0 were unavailable, 0 failed and 7 were disabled. For this story, 2 registered sources supplied useful evidence (1 primary, 1 corroborating, 0 contextual and 0 PoC/exploit references). 59 completed sources contained no matched information for this story.
Complete source-by-source audit 68 sources
| Source | Run result | Value | Why it was useful β or not |
|---|---|---|---|
| The Hacker Newsnews | ok9 records | Primary evidence1 matched items | Published the source report used to frame and date the event. |
| NVDcve | ok900 records | Corroborating1 matched items | A page from this source was opened and verified during focused research. |
| AlienVault OTXdark_web | ok10 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| BleepingComputernews | ok7 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| CIRCL CVEcve | ok30 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| CISA Alertsnews | ok empty0 records | Checked β no match | The source completed but returned no records in the collection scope. |
| CISA KEVkev | ok1670 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| Cisco PSIRTvendor_advisory | ok5324 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| Cisco Talosnews | ok empty0 records | Checked β no match | The source completed but returned no records in the collection scope. |
| deepdarkCTI CVE most exploiteddeepdarkcti | ok94 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI Discorddeepdarkcti | ok7 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI exploitsdeepdarkcti | ok24 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI forumsdeepdarkcti | ok264 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI malware as a servicedeepdarkcti | ok7 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI malware samplesdeepdarkcti | ok3 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI marketsdeepdarkcti | ok127 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI phishingdeepdarkcti | ok19 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI ransomware gangsdeepdarkcti | ok685 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI RATsdeepdarkcti | ok1 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI Telegram infostealerdeepdarkcti | ok130 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI Telegram threat actorsdeepdarkcti | ok1009 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI Twitter threat actorsdeepdarkcti | ok39 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| DNSDumpster domain IOC enrichmentresearch | ok1 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| Exploit-DBexploit_reference | ok empty0 records | Checked β no match | The source completed but returned no records in the collection scope. |
| FIRST EPSSepss | ok7785 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| Fortinet PSIRTvendor_advisory | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| GitHub topic: cveresearch | ok empty0 records | Checked β no match | The source completed but returned no records in the collection scope. |
| GitHub topic: exploitresearch | ok empty0 records | Checked β no match | The source completed but returned no records in the collection scope. |
| GitHub topic: penetration-testingresearch | ok empty0 records | Checked β no match | The source completed but returned no records in the collection scope. |
| GitHub topic: pocresearch | ok empty0 records | Checked β no match | The source completed but returned no records in the collection scope. |
| GitHub topic: vulnerabilityresearch | ok empty0 records | Checked β no match | The source completed but returned no records in the collection scope. |
| GreyNoiseexploit_reference | ok empty0 records | Checked β no match | The source completed but returned no records in the collection scope. |
| KrebsOnSecuritynews | ok empty0 records | Checked β no match | The source completed but returned no records in the collection scope. |
| LinkedIn RSS proxy feeds (disabled)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| MalwareBazaardark_web | ok2 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| Mastodon #cveresearch | ok20 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| Mastodon #cybersecurityresearch | ok16 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| Mastodon #exploitresearch | ok15 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| Mastodon #infosecresearch | ok20 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| Mastodon #malwareresearch | ok20 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| Mastodon #ransomwareresearch | ok19 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| Mastodon #threatintelresearch | ok15 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| Mastodon #vulnerabilityresearch | ok20 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| Metasploit module metadataexploit_reference | ok empty0 records | Checked β no match | The source completed but returned no records in the collection scope. |
| Microsoft MSRCvendor_advisory | ok1590 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| Microsoft Securitynews | ok1 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| MISP Galaxyresearch | ok1 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| MISP threat actor galaxyactor | ok0 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| Palo Alto Networks PSIRTvendor_advisory | ok25 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| ProjectDiscovery nuclei templatesexploit_reference | ok empty0 records | Checked β no match | The source completed but returned no records in the collection scope. |
| Rapid7news | ok1 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| Reddit r/AskNetsec (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| Reddit r/cybersecurity (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| Reddit r/malware (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| Reddit r/netsec (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| Reddit r/ReverseEngineering (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| SANS ISCnews | ok1 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| Shadowserver public aggregate honeypot observationsexploit_reference | ok empty0 records | Checked β no match | The source completed but returned no records in the collection scope. |
| Shodanresearch | ok3 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| Sigma Rulesresearch | ok3 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| Sophos IOCsresearch | ok empty0 records | Checked β no match | The source completed but returned no records in the collection scope. |
| ThreatFoxthreat_intelligence | ok100 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| UK NCSCnews | ok empty0 records | Checked β no match | The source completed but returned no records in the collection scope. |
| Unit42 IOCsresearch | ok empty0 records | Checked β no match | The source completed but returned no records in the collection scope. |
| URLhausdark_web | ok10 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| VirusTotal Community IOC enrichmentresearch | ok4 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| VulnCheck KEVkev | ok500 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| Vulnerability Lookupcve | ok30 records | Checked β no match | The source completed, but none of its retained records matched this story. |
Additional verified pages 1 opened outside the registered collection
Technical references2
Repository captured from the source article as technical context; not validated as PoC or exploit code.
Repository captured from the source article as technical context; not validated as PoC or exploit code.
OSINT / dark-web chatter1
News reporting on live exploitation and scanning activity