Two critical vulnerabilities affecting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, a web-based SCADA/HMI software, are currently being exploited by attackers. Reports from watchTowr and VulnCheck indicate that these vulnerabilities are leading to malicious scanning and exploitation efforts.
The first vulnerability, CVE-2026-64849 (CVSS score: 9.3), is an unauthenticated Server-Side Request Forgery (SSRF) flaw in MLflow. This vulnerability allows attackers who can access the Tracking Server to issue HTTP requests to arbitrary internal cloud metadata endpoints, potentially extracting sensitive data. It affects versions prior to 3.15.0. According to watchTowr, attackers have been exploiting this vulnerability to directly access cloud metadata services and exfiltrate cloud credentials and secrets. They detected scanning for exposed MLflow instances shortly after the CVE was assigned on August 17, 2026.
Yordan Ganchev, a principal threat intelligence specialist at watchTowr, noted that the vulnerability allows attackers to exploit flaws in MLflow’s model-registry webhooks, enabling them to proxy requests through the affected system and interact with internal services. Organizations using MLflow are advised to prioritize patching affected systems and reviewing audit logs for signs of compromise.
The second vulnerability, CVE-2026-25895 (CVSS score: 9.5), involves a missing authentication for a critical function in FUXA, allowing unauthenticated remote attackers to write arbitrary files to the server file system, potentially leading to remote code execution. VulnCheck reported that scanning for this vulnerability began on August 18, 2026, with a single IP address identified as broadly scanning for vulnerable FUXA instances, of which approximately 60 are exposed to the public internet.
Caitlin Condon, vice president of research at VulnCheck, mentioned that attackers are attempting to overwrite files via the CVE-2026-25895 path traversal, although no remote code execution payloads have been observed yet. Additionally, two other vulnerabilities in FUXA have been actively exploited over the past year.
For more details, refer to the report by The Hacker News.
Follow Cyber Warriors Middle East for further global cybersecurity developments.


