CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4617

As cited

Copy frozen at (site build).

vulnerabilities

Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets

Two critical vulnerabilities in MLflow (an open-source AI platform) and FUXA (an open-source OT/industrial automation software) are under active malicious scanning and exploitation, according to reports from watchTowr and VulnCheck. The MLflow flaw enables server-side request forgery (SSRF) attacks to extract cloud credentials and secrets. Both projects require immediate patching to prevent further compromise.

Why it matters: Organizations running MLflow or FUXA in production face credential theft and unauthorized access; teams should prioritize identifying affected instances and applying patches or network controls immediately.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets

MLflow, an open-source artificial intelligence platform, and FUXA, a web-based supervisory control and data acquisition and human-machine interface software for operational technology environments, contain critical vulnerabilities that attackers are actively scanning and exploiting.

Why it matters: Organizations running MLflow or FUXA in production face immediate risk of credential theft and system compromise; security teams should immediately verify whether these platforms are deployed and apply available patches or mitigations.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary