Open Source

Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets

· August 18, 2026
Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets

What happened

Attackers are exploiting two critical vulnerabilities in MLflow and FUXA, open-source platforms used in AI and industrial automation respectively. MLflow suffers from a server-side request forgery (SSRF) flaw that allows attackers to trick the system into making unauthorized requests. These requests can reach internal or cloud services and steal sensitive cloud credentials and secrets. FUXA, a web-based SCADA and HMI system for operational technology, also faces similar risks from vulnerabilities exposing industrial control systems.

The risk

The MLflow SSRF flaw puts cloud environments at serious risk by allowing bad actors to access authentication tokens and secret keys typically protected inside the infrastructure. Any stolen credentials can lead to further compromise across cloud accounts, including data breaches or service interruptions. Exploitation attempts targeting FUXA increase the risk of sabotage or espionage in industrial systems where uptime and safety are critical. These vulnerabilities invite malicious scanning and active exploitation already, raising the urgency level.

Why it matters

Both MLflow and FUXA support important AI and automation workflows in their respective sectors. MLflow is widely adopted for machine learning lifecycle management, making this flaw a direct threat to AI development environments and their cloud infrastructure. Meanwhile, FUXA underpins industrial operations, so vulnerabilities here risk production downtime and physical hazards. The combination highlights the expanding attack surface as AI workflows and industrial processes converge on web-accessible platforms.

Who should pay attention

Developers and operators running MLflow in cloud environments must urgently verify patches and review permissions limiting internal cloud resource access. Industrial operators and automation engineers relying on FUXA need immediate vulnerability assessments and stronger network segmentation to prevent external access to critical OT assets. Cloud security teams should also monitor for unusual SSRF patterns and tighten credential storage and rotation policies.

What to watch next

Stay tuned for official security patches and updates from MLflow and FUXA projects. Expect heightened scanning activity and possibly more SSRF-related exploits targeting AI and industrial platforms as attackers adapt. Cloud providers may roll out enhanced SSRF detection and credential protection guidance especially for AI tooling environments. The broader trend of AI and OT platform vulnerabilities attracting active exploitation is likely to accelerate, making rapid response essential.

AI Quick Briefs Editorial Desk

Stay ahead of AI Get the most important AI news delivered to your inbox — free.