The digital frontier of artificial intelligence and industrial automation is currently under siege, as two critical vulnerabilities in widely used open-source platforms, MLflow and FUXA, are actively being exploited. Cybersecurity researchers from watchTowr and VulnCheck have issued urgent warnings regarding malicious scanning and exploitation attempts targeting these flaws, which could lead to devastating consequences, from cloud credential theft to full remote code execution.
MLflow’s SSRF Flaw: A Gateway to Cloud Secrets
MLflow, a popular open-source platform designed to manage the machine learning lifecycle, is grappling with a severe Server-Side Request Forgery (SSRF) vulnerability, identified as
CVE-2026-64849. This critical flaw, boasting a CVSS score of 9.3, allows unauthenticated attackers who can reach the MLflow Tracking Server to initiate arbitrary HTTP requests to internal cloud metadata endpoints. The grave implication? Attackers can effortlessly extract highly sensitive data, including cloud credentials and other confidential secrets, effectively gaining unauthorized access to an organization’s cloud infrastructure.
Affected MLflow Versions
Organizations utilizing MLflow versions prior to 3.15.0 are particularly vulnerable and urged to update immediately to mitigate this significant risk.
FUXA’s RCE Threat: Industrial Systems at Risk
Adding to the growing concerns, FUXA, an open-source, web-based SCADA/HMI software crucial for operational technology (OT) and industrial automation environments, is also facing active exploitation. The vulnerability, tracked as
CVE-2026-25895 and rated with an alarming CVSS score of 9.5, stems from a critical lack of authentication combined with a path traversal flaw. This dangerous combination enables an unauthenticated, remote attacker to write arbitrary files to the server’s file system, ultimately paving the way for complete remote code execution (RCE). The potential for disruption and control over industrial processes is immense, posing a direct threat to critical infrastructure.
Affected FUXA Versions
While the full range of affected FUXA versions was not completely specified in the initial report, the high CVSS score and nature of the vulnerability demand immediate attention and investigation by all FUXA users.
The Broader Implications for AI and OT Security
These dual threats underscore a critical trend: the increasing targeting of platforms that bridge the gap between cutting-edge AI development and vital industrial operations. Compromising MLflow can expose valuable AI models, data, and the underlying cloud infrastructure, while exploiting FUXA directly jeopardizes the integrity and safety of operational technology systems. The convergence of IT and OT security is more critical than ever, demanding a unified and proactive defense strategy.
Urgent Call to Action
Organizations leveraging MLflow and FUXA must prioritize immediate action. This includes:
- Patching: Update MLflow to version 3.15.0 or later without delay. For FUXA, consult official advisories for patching instructions and apply them promptly.
- Network Segmentation: Ensure MLflow Tracking Servers and FUXA instances are properly segmented and not directly exposed to untrusted networks.
- Monitoring: Implement robust logging and monitoring to detect suspicious activity indicative of SSRF attempts or unauthorized file writes.
- Authentication: Review and strengthen authentication mechanisms across all critical systems, especially those managing sensitive data or industrial controls.
The active exploitation of these vulnerabilities serves as a stark reminder of the persistent and evolving threats in the cybersecurity landscape. Vigilance, rapid response, and adherence to best security practices are paramount to safeguarding both AI innovation and industrial resilience.
For more details, visit our website.
Source: Link









Leave a comment