BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Critical MLflow and FUXA flaws exploited in wild

Critical MLflow and FUXA flaws exploited for cloud credential theft and RCE.

  • Two critical vulnerabilities in MLflow (CVE-2026-64849, CVSS 9.3) and FUXA (CVE-2026-25895, CVSS 9.5) are under active exploitation.
  • Attackers are exploiting the MLflow flaw to reach cloud metadata services and exfiltrate credentials and secrets.
  • The FUXA vulnerability allows unauthenticated remote code execution and path traversal, with broad scanning detected.

WatchTowr and VulnCheck report that malicious actors are actively scanning and exploiting two severe vulnerabilities in open-source platforms MLflow and FUXA, risking cloud credentials and operational technology systems. The first flaw, CVE-2026-64849 (CVSS 9.3), is an unauthenticated Server-Side Request Forgery (SSRF) in MLflow that allows attackers to issue HTTP requests to arbitrary internal cloud metadata endpoints. WatchTowr stated that “attackers are exploiting… to reach cloud metadata services directly, and exfiltrating cloud credentials and secrets” within hours of the CVE being assigned on August 17, 2026.

- Advertisement -

The security bug bypasses prior fixes through mishandled web redirects in MLflow’s model-registry webhooks, according to watchTowr’s Yordan Ganchev. Organizations running MLflow should prioritize patching, review audit logs for compromise, and check for exposed sensitive credentials. The second vulnerability, CVE-2026-25895 (CVSS 9.5), affects FUXA, a web-based SCADA/HMI software, and enables unauthenticated path traversal leading to remote code execution.

VulnCheck detected malicious scanning for this flaw beginning August 18, 2026, with a single IP address broadly scanning the internet for vulnerable FUXA instances, of which about 60 are publicly exposed. Caitlin Condon of VulnCheck noted that the attacker request attempts to overwrite main.js via path traversal, though no RCE payloads have been dropped yet. Meanwhile, two older FUXA vulnerabilities, CVE-2026-25939 and CVE-2023-33831, have also seen active exploitation dating back to November 2025.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Tesla signs $30B unused credit lines for the AI and robotics

Tesla signed $30 billion in unused senior unsecured bank facilities, including a $20 billion...

New Spectre-v2 CPU Variant ‘BTR’ Hits JIT Engines

Academics disclosed a new Spectre-v2 CPU vulnerability variant, Branch Target Reuse (BTR), affecting JIT...

Cboe, S&P Extend Deal, Eye Tokenized Options

Cboe Global Markets and S&P Dow Jones Indices extended their exclusive licensing agreement through...

OpenAI launches Dots assistant, seeks $30B funding

OpenAI launched "Dots," a persistent virtual assistant operating computers and debugging software autonomously.The company...

Healey jabs Farage with ‘BTC account’ Truss comparison

UK Chancellor John Healey mocked Nigel Farage's fiscal plans by comparing them to a...

Must Read

Top 9 VPNs That Accept Bitcoin And Crypto

CyberGhost | FastVPN | TorGuard | Private Internet Access | ExpressVPN | NordVPN | Private VPN | SurfShark | AirVPN | Why Buy VPN...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading