Articles tagged SSRF
-
VulnerabilityMailgun for WordPress SSRF (CVE-2026-78003)
CVE-2026-78003 is a CVSS 9.8 SSRF flaw in Mailgun for WordPress enabling admin takeover via intercepted password resets, reported exploited by VulnCheck.
-
VulnerabilityMonsta FTP SSRF (CVE-2026-60105)
CVE-2026-60105 is a CVSS 8.6 SSRF in Monsta FTP via an IP-blocklist bypass, reported exploited by VulnCheck alone.
-
Vulnerability2 CVEs: Kan & Arcane (CVE-2026-32255)
Kan (CVE-2026-32255, CVSS 8.6) and Arcane (CVE-2026-40242, 7.2) each expose an unauthenticated URL-fetching endpoint. Both VulnCheck KEV-listed Sept. 17, 2026.
-
Vulnerability2 SonicWall SMA1000 Appliances CVEs (CVE-2026-83548)
CVE-2026-83548 is a CVSS 10.0 pre-auth SSRF in SonicWall SMA1000 appliances, KEV-listed Sept. 2, 2026 beside CVE-2026-83549, a post-auth command injection.
-
Vulnerability9 CVEs: CodeWhale & deepseek-tui (CVE-2026-75913)
Nine CodeWhale AI coding-agent CVEs: arbitrary file write, an SSRF bypass, two auto-approved RCE paths, and five more approval-gate and sandbox failures.
-
Vulnerability5 CVEs Across 3 Vendors (CVE-2026-59971)
Five 2026 MCP-server CVEs: unauthenticated SQL execution (CVSS 10) in MySQL MCP Server, a code-execution flaw in functype-mcp-server, and three CKAN issues.
-
Vulnerability10 n8n CVEs (CVE-2026-86075)
Ten further n8n CVEs: unauthenticated storage exhaustion, credential-exfiltration paths, a webhook signature bypass, and a KEV-listed flaw.
-
Vulnerability10 CVEs: vLLM & vLLM Hardware Plugin for Intel Gaudi (CVE-2026-73560)
Ten 2026 vLLM CVEs assessed against NVD, GitHub Advisory, and CVE.org data: an SSRF and file-read flaw, a cross-user data leak, and an OpenAI API auth bypass.
-
Vulnerability6 CVEs Across 6 Vendors (CVE-2026-86217)
A roundup of six low-severity, unrelated vulnerabilities disclosed in September 2026: information disclosure and XSS in several small PHP student/hobby projects, an out-of-bounds read in Valkey requiring cluster-mode plus attacker file access, and a disputed SSRF report in OpenAgents.
-
VulnerabilitySmarty SSRF (CVE-2026-62993)
CVE-2026-62993 lets an open redirect on a trusted host bypass Smarty's trusted_uri policy for {fetch}, enabling server-side request forgery to internal targets, fixed in 5.8.2.