Recent findings reveal that attackers are leveraging a significant Server-Side Request Forgery (SSRF) vulnerability in MLflow, an open-source artificial intelligence platform, to steal sensitive cloud credentials. This vulnerability, identified as CVE-2026-64849, has a high severity rating with a CVSS score of 9.3.
Details of the Vulnerability
The SSRF flaw allows an unauthenticated attacker with access to the MLflow Tracking Server to send HTTP requests to arbitrary internal cloud metadata endpoints, thereby extracting sensitive data. The affected versions are those prior to 3.15.0.
Active Exploitation Observed
According to reports from watchTowr and VulnCheck, malicious actors began scanning for exposed MLflow instances shortly after the CVE was assigned on August 17, 2026. Evidence indicates that attackers are using this vulnerability to directly access cloud metadata services and exfiltrate credentials and secrets from internal IP addresses.
Recommendations for Affected Organizations
Organizations utilizing MLflow are advised to prioritize patching their systems to mitigate this vulnerability. Additionally, they should review audit logs for any signs of compromise and verify whether sensitive credentials have been exposed.
Related Vulnerabilities in FUXA
Another vulnerability, CVE-2026-25895, affecting FUXA, an open-source web-based SCADA/HMI software, has also been identified. This flaw, which has a CVSS score of 9.5, allows unauthenticated remote attackers to write arbitrary files to the server file system, potentially leading to remote code execution. The affected versions are those up to and including 1.2.9.
Malicious scanning for this vulnerability began on August 18, 2026, with reports of attempts to overwrite files on vulnerable FUXA installations. Currently, no remote code execution payloads have been observed.
In summary, both vulnerabilities highlight the ongoing risks associated with exposed systems and the importance of timely updates and monitoring for organizations in the AI and operational technology sectors.
This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.








