<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #SSRF</title><description>Cybersecurity articles tagged #SSRF on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>CVE-2026-83548: SonicWall SMA1000 SSRF Under Active Exploitation</title><link>https://runtimerebel.com/blog/cve-2026-83548-sonicwall-sma1000-ssrf-under-active-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-83548-sonicwall-sma1000-ssrf-under-active-exploitation</guid><description>A critical server-side request forgery (SSRF) vulnerability, CVE-2026-83548, in SonicWall SMA1000 Appliances is under active exploitation.</description><pubDate>Wed, 02 Sep 2026 19:13:21 GMT</pubDate><category>SonicWall</category><category>SMA1000</category><category>SSRF</category><category>Vulnerability</category><category>CISA KEV</category></item><item><title>Detecting SSRF Hostname Obfuscation: 1u.ms and Cloud Metadata</title><link>https://runtimerebel.com/blog/detecting-ssrf-hostname-obfuscation-1u-ms-and-cloud-metadata</link><guid isPermaLink="true">https://runtimerebel.com/blog/detecting-ssrf-hostname-obfuscation-1u-ms-and-cloud-metadata</guid><description>Attackers are leveraging hostnames and services like 1u.ms to obfuscate IP addresses (e.g., 169.254.169.254), bypassing traditional SSRF blocklist defenses.</description><pubDate>Tue, 25 Aug 2026 16:30:00 GMT</pubDate><category>SSRF</category><category>Obfuscation</category><category>Cloud Security</category><category>Threat Intelligence</category><category>1u Ms</category></item><item><title>SSRF Scans Target Cloud Metadata Service for Credential Access</title><link>https://runtimerebel.com/blog/ssrf-scans-target-cloud-metadata-service-for-credential-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/ssrf-scans-target-cloud-metadata-service-for-credential-access</guid><description>Attackers are conducting widespread scans for Server-Side Request Forgery (SSRF) vulnerabilities to access cloud metadata services and retrieve sensitive IAM credentials.</description><pubDate>Wed, 19 Aug 2026 16:24:58 GMT</pubDate><category>SSRF</category><category>Cloud Security</category><category>IAM</category><category>Credential Theft</category><category>Metadata Service</category></item><item><title>MLflow CVE-2026-64849 Exploited: Cloud Credential Theft Via SSRF</title><link>https://runtimerebel.com/blog/mlflow-cve-2026-64849-exploited-cloud-credential-theft-via-ssrf</link><guid isPermaLink="true">https://runtimerebel.com/blog/mlflow-cve-2026-64849-exploited-cloud-credential-theft-via-ssrf</guid><description>Attackers exploit a critical MLflow SSRF vulnerability (CVE-2026-64849) to steal cloud credentials.</description><pubDate>Wed, 19 Aug 2026 08:25:32 GMT</pubDate><category>SSRF</category><category>Cloud Security</category><category>MLflow</category><category>FUXA</category><category>CVE-2026-64849</category></item><item><title>CVE-2026-58231: SAP Commerce Cloud Unauthenticated RCE Flaw</title><link>https://runtimerebel.com/blog/cve-2026-58231-sap-commerce-cloud-unauthenticated-rce-flaw</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-58231-sap-commerce-cloud-unauthenticated-rce-flaw</guid><description>SAP has patched a critical flaw, CVE-2026-58231, in Commerce Cloud Data Hub Adapter allowing unauthenticated arbitrary code execution. Immediate action is urged.</description><pubDate>Sat, 15 Aug 2026 00:40:41 GMT</pubDate><category>RCE</category><category>SSRF</category><category>CVE-2026-58231</category><category>SAP Commerce Cloud</category><category>Unauthenticated</category></item><item><title>SonicWall SMA 1000 Series Zero-Days CVE-2026-15409 - Mitigation Guide</title><link>https://runtimerebel.com/blog/sonicwall-sma-1000-series-zero-days-cve-2026-15409-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/sonicwall-sma-1000-series-zero-days-cve-2026-15409-mitigation-guide</guid><description>SonicWall warns of active exploitation of two zero-day vulnerabilities in SMA 1000 series appliances, including a critical CVSS 10.0 SSRF (CVE-2026-15409).</description><pubDate>Wed, 15 Jul 2026 10:05:11 GMT</pubDate><category>SonicWall</category><category>SMA1000</category><category>CVE-2026-15409</category><category>Zero-Day</category><category>SSRF</category><category>Remote Command Execution</category></item><item><title>Cisco CUCM SSRF Flaw: Rapid Exploitation &amp; Root Privilege Escalation</title><link>https://runtimerebel.com/blog/cisco-cucm-ssrf-flaw-rapid-exploitation-root-privilege-escalation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisco-cucm-ssrf-flaw-rapid-exploitation-root-privilege-escalation</guid><description>Attackers are rapidly weaponizing a Cisco Unified CM server-side request forgery (SSRF) flaw, escalating privileges to root. Immediate patching is critical.</description><pubDate>Fri, 26 Jun 2026 05:32:30 GMT</pubDate><category>Cisco Unified CM</category><category>Cisco Unified CM SME</category><category>SSRF</category><category>Privilege Escalation</category><category>Root Access</category><category>Active Exploitation</category></item><item><title>CVE-2026-20230: Cisco Unified CM SSRF Actively Exploited</title><link>https://runtimerebel.com/blog/cve-2026-20230-cisco-unified-cm-ssrf-actively-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-20230-cisco-unified-cm-ssrf-actively-exploited</guid><description>Cisco Unified CM Server is vulnerable to CVE-2026-20230, a high-severity SSRF flaw now under active exploitation. Patch immediately to prevent attacks.</description><pubDate>Wed, 24 Jun 2026 00:53:37 GMT</pubDate><category>CVE-2026-20230</category><category>Cisco Unified Communications Manager</category><category>SSRF</category><category>Exploitation</category><category>Vulnerability</category></item><item><title>Dify AI Platform Vulnerabilities: How to Mitigate DifyTap Exploit</title><link>https://runtimerebel.com/blog/dify-ai-platform-vulnerabilities-how-to-mitigate-difytap-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/dify-ai-platform-vulnerabilities-how-to-mitigate-difytap-exploit</guid><description>Researchers discover DifyTap vulnerabilities in the Dify AI platform, allowing attackers to exfiltrate chat histories and secrets through SSRF and RCE.</description><pubDate>Tue, 23 Jun 2026 13:17:28 GMT</pubDate><category>Dify</category><category>AI Security</category><category>CVE-2024-38505</category><category>CVE-2024-38506</category><category>SSRF</category><category>RCE</category></item><item><title>Cisco Unified CM RCE via CVE-2026-20230 — Mitigation Guide</title><link>https://runtimerebel.com/blog/cisco-unified-cm-rce-via-cve-2026-20230-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisco-unified-cm-rce-via-cve-2026-20230-mitigation-guide</guid><description>Cisco patches CVE-2026-20230, a high-severity SSRF in Unified Communications Manager. Learn how public PoC code impacts your security and find remediation steps.</description><pubDate>Thu, 04 Jun 2026 17:08:33 GMT</pubDate><category>Cisco</category><category>CVE-2026-20230</category><category>Unified CM</category><category>RCE</category><category>SSRF</category></item><item><title>Cisco Unified CM SSRF CVE-2024-20455 — Public PoC Mitigation Guide</title><link>https://runtimerebel.com/blog/cisco-unified-cm-ssrf-cve-2024-20455-public-poc-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisco-unified-cm-ssrf-cve-2024-20455-public-poc-mitigation-guide</guid><description>Cisco warns of critical SSRF vulnerabilities in Unified CM with public PoC exploit code. Learn how to detect and patch CVE-2024-20455 to protect your network.</description><pubDate>Thu, 04 Jun 2026 09:26:39 GMT</pubDate><category>Cisco</category><category>CVE-2024-20455</category><category>Unified CM</category><category>SSRF</category><category>Vulnerability Management</category></item><item><title>VMware Workspace ONE Access RCE via CVE-2022-22960 — Patch Now</title><link>https://runtimerebel.com/blog/vmware-workspace-one-access-rce-via-cve-2022-22960-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/vmware-workspace-one-access-rce-via-cve-2022-22960-patch-now</guid><description>VMware Workspace ONE Access and Identity Manager face critical RCE vulnerabilities (CVE-2022-22960, CVE-2022-22957) actively exploited.</description><pubDate>Fri, 29 May 2026 05:34:10 GMT</pubDate><category>VMware</category><category>Workspace ONE Access</category><category>Identity Manager</category><category>CVE-2022-22960</category><category>CVE-2022-22957</category><category>CVE-2022-22954</category><category>CVE-2022-22958</category><category>RCE</category><category>SSRF</category><category>Authentication Bypass</category><category>Zero-Day</category></item><item><title>Cisco ISE and Nexus Dashboard RCE via CVE-2024-20469 — Mitigation Guide</title><link>https://runtimerebel.com/blog/cisco-ise-and-nexus-dashboard-rce-via-cve-2024-20469-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisco-ise-and-nexus-dashboard-rce-via-cve-2024-20469-mitigation-guide</guid><description>Cisco patches high-severity vulnerabilities in ISE, Nexus Dashboard, and Catalyst Center that enable RCE, SSRF, and DoS attacks. Secure your enterprise today.</description><pubDate>Thu, 07 May 2026 12:47:47 GMT</pubDate><category>Cisco Ise</category><category>Nexus Dashboard</category><category>CVE-2024-20469</category><category>RCE</category><category>SSRF</category></item><item><title>LMDeploy SSRF: CVE-2026-33626 Exploit and Mitigation Guide</title><link>https://runtimerebel.com/blog/lmdeploy-ssrf-cve-2026-33626-exploit-and-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/lmdeploy-ssrf-cve-2026-33626-exploit-and-mitigation-guide</guid><description>Attackers are actively exploiting CVE-2026-33626, a high-severity SSRF in LMDeploy, to access sensitive LLM data. Learn how to detect and patch this flaw.</description><pubDate>Fri, 24 Apr 2026 08:48:12 GMT</pubDate><category>CVE-2026-33626</category><category>LMDeploy</category><category>SSRF</category><category>LLM Security</category><category>Active Exploitation</category></item><item><title>UAT-10608 Exploits Next.js CVE-2024-34351 via React2Shell Script</title><link>https://runtimerebel.com/blog/uat-10608-exploits-next-js-cve-2024-34351-via-react2shell-script</link><guid isPermaLink="true">https://runtimerebel.com/blog/uat-10608-exploits-next-js-cve-2024-34351-via-react2shell-script</guid><description>Threat actor UAT-10608 is leveraging an automated script to exploit a Next.js SSRF flaw, exfiltrating credentials and environment secrets from web applications.</description><pubDate>Mon, 06 Apr 2026 16:22:28 GMT</pubDate><category>CVE-2024-34351</category><category>UAT 10608</category><category>Next Js</category><category>React2Shell</category><category>SSRF</category></item><item><title>Mitigating Attack Surface Expansion in Distributed LLM Infrastructure</title><link>https://runtimerebel.com/blog/mitigating-attack-surface-expansion-in-distributed-llm-infrastructure</link><guid isPermaLink="true">https://runtimerebel.com/blog/mitigating-attack-surface-expansion-in-distributed-llm-infrastructure</guid><description>An analysis of the security implications of exposing inference servers, vector databases, and orchestration APIs in self-hosted LLM environments.</description><pubDate>Mon, 23 Feb 2026 12:20:07 GMT</pubDate><category>LLM</category><category>API Security</category><category>Inference</category><category>SSRF</category><category>Orchestration</category></item></channel></rss>