Advertisement
CVE-2026-83548: SonicWall SMA1000 SSRF Under Active Exploitation
A critical server-side request forgery (SSRF) vulnerability, CVE-2026-83548, in SonicWall SMA1000 Appliances is under active exploitation.
Detecting SSRF Hostname Obfuscation: 1u.ms and Cloud Metadata
Attackers are leveraging hostnames and services like 1u.ms to obfuscate IP addresses (e.g., 169.254.169.254), bypassing traditional SSRF blocklist defenses.
SSRF Scans Target Cloud Metadata Service for Credential Access
Attackers are conducting widespread scans for Server-Side Request Forgery (SSRF) vulnerabilities to access cloud metadata services and retrieve sensitive IAM credentials.
MLflow CVE-2026-64849 Exploited: Cloud Credential Theft Via SSRF
Attackers exploit a critical MLflow SSRF vulnerability (CVE-2026-64849) to steal cloud credentials.
CVE-2026-58231: SAP Commerce Cloud Unauthenticated RCE Flaw
SAP has patched a critical flaw, CVE-2026-58231, in Commerce Cloud Data Hub Adapter allowing unauthenticated arbitrary code execution. Immediate action is urged.
SonicWall SMA 1000 Series Zero-Days CVE-2026-15409 - Mitigation Guide
SonicWall warns of active exploitation of two zero-day vulnerabilities in SMA 1000 series appliances, including a critical CVSS 10.0 SSRF (CVE-2026-15409).
Advertisement
Cisco CUCM SSRF Flaw: Rapid Exploitation & Root Privilege Escalation
Attackers are rapidly weaponizing a Cisco Unified CM server-side request forgery (SSRF) flaw, escalating privileges to root. Immediate patching is critical.
CVE-2026-20230: Cisco Unified CM SSRF Actively Exploited
Cisco Unified CM Server is vulnerable to CVE-2026-20230, a high-severity SSRF flaw now under active exploitation. Patch immediately to prevent attacks.
Dify AI Platform Vulnerabilities: How to Mitigate DifyTap Exploit
Researchers discover DifyTap vulnerabilities in the Dify AI platform, allowing attackers to exfiltrate chat histories and secrets through SSRF and RCE.
Cisco Unified CM RCE via CVE-2026-20230 — Mitigation Guide
Cisco patches CVE-2026-20230, a high-severity SSRF in Unified Communications Manager. Learn how public PoC code impacts your security and find remediation steps.
Cisco Unified CM SSRF CVE-2024-20455 — Public PoC Mitigation Guide
Cisco warns of critical SSRF vulnerabilities in Unified CM with public PoC exploit code. Learn how to detect and patch CVE-2024-20455 to protect your network.
VMware Workspace ONE Access RCE via CVE-2022-22960 — Patch Now
VMware Workspace ONE Access and Identity Manager face critical RCE vulnerabilities (CVE-2022-22960, CVE-2022-22957) actively exploited.
Cisco ISE and Nexus Dashboard RCE via CVE-2024-20469 — Mitigation Guide
Cisco patches high-severity vulnerabilities in ISE, Nexus Dashboard, and Catalyst Center that enable RCE, SSRF, and DoS attacks. Secure your enterprise today.
LMDeploy SSRF: CVE-2026-33626 Exploit and Mitigation Guide
Attackers are actively exploiting CVE-2026-33626, a high-severity SSRF in LMDeploy, to access sensitive LLM data. Learn how to detect and patch this flaw.
UAT-10608 Exploits Next.js CVE-2024-34351 via React2Shell Script
Threat actor UAT-10608 is leveraging an automated script to exploit a Next.js SSRF flaw, exfiltrating credentials and environment secrets from web applications.
Mitigating Attack Surface Expansion in Distributed LLM Infrastructure
An analysis of the security implications of exposing inference servers, vector databases, and orchestration APIs in self-hosted LLM environments.