Bottom line: Active attacks are exploiting an SSRF vulnerability in MLflow to harvest cloud credentials, while a flaw in the OT software FUXA is being exploited in parallel.
Security researchers from watchTowr and VulnCheck are independently reporting active scanning and exploitation activity against critical vulnerabilities in the open-source AI platform MLflow as well as in the SCADA/HMI software FUXA. Both AI infrastructure and OT environments are affected.
MLflow is a widely used open-source platform for managing the machine learning lifecycle, deployed at numerous organizations for experiment tracking, model registry, and deployment. According to reports from watchTowr and VulnCheck, MLflow contains a Server-Side Request Forgery (SSRF) vulnerability that allows attackers to trick the server into making requests to internal or cloud-internal resources. In parallel, the researchers are observing exploitation attempts against FUXA, a web-based SCADA/HMI software for operational technology (OT) and industrial automation.
The SSRF flaw in MLflow can, under certain circumstances, be used to reach cloud metadata endpoints — such as those through which cloud providers issue temporary credentials for connected services. If access succeeds, attackers can harvest cloud credentials and other secrets and abuse them for lateral movement into cloud resources or data exfiltration. For organizations running MLflow in production environments or with connections to cloud infrastructure (AWS, Azure, GCP), this creates a direct risk to identity and access management.
The simultaneous exploitation of a vulnerability in FUXA shows that attackers are currently targeting both AI tooling and OT/ICS systems as attack surfaces. For CISOs, this means checking MLflow instances for internet exposure as well as for network segmentation against cloud metadata services. Recommended measures include hardening IMDS access (e.g., via IMDSv2 on AWS), restricting outbound connections from MLflow servers, and reviewing existing patches or version levels once official advisories from the projects become available.
Since the original report does not cite a specific CVE number, affected version numbers, or a patch date, security teams should closely monitor the statements from watchTowr and VulnCheck as well as official MLflow and FUXA advisories in order to concretely assess exposure and required action in their own environments.
Source: thehackernews.com · Published August 18, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.