Executive Summary

In August 2026, two critical vulnerabilities were actively exploited: CVE-2026-64849 in MLflow and CVE-2026-25895 in FUXA. The MLflow vulnerability allowed unauthenticated attackers to perform Server-Side Request Forgery (SSRF) attacks, enabling access to internal cloud metadata endpoints and extraction of sensitive data. The FUXA vulnerability permitted unauthenticated remote attackers to write arbitrary files to the server filesystem, potentially leading to remote code execution. Both vulnerabilities were promptly patched in subsequent software releases.

The exploitation of these vulnerabilities underscores the persistent targeting of open-source platforms by threat actors. Organizations are urged to prioritize timely patching, conduct thorough audits for signs of compromise, and implement robust security measures to protect against similar threats.

Why This Matters Now

The active exploitation of these vulnerabilities highlights the urgent need for organizations to update their MLflow and FUXA installations to the latest versions to prevent unauthorized access and potential system compromises.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

MLflow's CVE-2026-64849 is an SSRF vulnerability allowing unauthorized access to internal cloud metadata. FUXA's CVE-2026-25895 is a path traversal flaw enabling arbitrary file writes and potential remote code execution.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The attacker's ability to exploit the SSRF vulnerability may have been constrained, reducing the likelihood of unauthorized access to internal metadata endpoints.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: The attacker's ability to escalate privileges may have been limited, reducing the scope of unauthorized access within the cloud environment.

Lateral Movement

Control: East-West Traffic Security

Mitigation: The attacker's lateral movement could have been constrained, limiting their ability to access additional cloud services and resources.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: The attacker's ability to establish and maintain command and control channels may have been reduced, limiting persistent access.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: The attacker's ability to exfiltrate sensitive data could have been limited, reducing the risk of data loss.

Impact (Mitigations)

The attacker's ability to disrupt services or deploy malicious payloads may have been constrained, reducing the potential impact on cloud operations.

Impact at a Glance

Affected Business Functions

  • SCADA Operations
  • Industrial Automation Control
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $50,000

Data Exposure

Potential exposure of operational technology configurations and control data.

Recommended Actions

  • Implement Zero Trust Segmentation to restrict unauthorized access and limit lateral movement within the cloud environment.
  • Deploy Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
  • Utilize Multicloud Visibility & Control to detect and respond to anomalous activities across cloud services.
  • Apply Inline IPS (Suricata) to identify and block known exploit patterns and malicious payloads.
  • Regularly update and patch MLflow and other critical systems to mitigate known vulnerabilities.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image