Glossary
SSRF
Server-Side Request Forgery — A vulnerability that tricks a server into making an unintended network request on the attacker's behalf, often used to reach internal systems that are not directly accessible from the internet, such as cloud metadata services. It has been the root cause of several high-profile cloud data breaches.
Recent coverage mentioning SSRF
CVE-2026-83548: SonicWall SMA1000 SSRF Under Active Exploitation
A critical server-side request forgery (SSRF) vulnerability, CVE-2026-83548, in SonicWall SMA1000 Appliances is under active exploitation.
CVE-2026-49869: Kestra OSS OS Command Injection Exploited
CISA has added CVE-2026-49869, an OS command injection in Kestra OSS, to its KEV catalog, confirming active exploitation by unauthenticated attackers.
Detecting SSRF Hostname Obfuscation: 1u.ms and Cloud Metadata
Attackers are leveraging hostnames and services like 1u.ms to obfuscate IP addresses (e.g., 169.254.169.254), bypassing traditional SSRF blocklist defenses.
SSRF Scans Target Cloud Metadata Service for Credential Access
Attackers are conducting widespread scans for Server-Side Request Forgery (SSRF) vulnerabilities to access cloud metadata services and retrieve sensitive IAM credentials.
MLflow CVE-2026-64849 Exploited: Cloud Credential Theft Via SSRF
Attackers exploit a critical MLflow SSRF vulnerability (CVE-2026-64849) to steal cloud credentials.
CVE-2026-58231: SAP Commerce Cloud Unauthenticated RCE Flaw
SAP has patched a critical flaw, CVE-2026-58231, in Commerce Cloud Data Hub Adapter allowing unauthenticated arbitrary code execution. Immediate action is urged.
Advertisement