CVE‑2026‑40175 could be used in an attack chain to allow for remote code execution or full cloud compromise
CVE‑2026‑40175 could be used in an attack chain to allow for remote code execution or full cloud compromise
The following platforms are known to be affected:
Proof-of-Concept for CVE-2026-40175
A public proof‑of‑concept exploit has been released demonstrating exploitation of CVE‑2026‑40175 via a chained “gadget” attack.
The NHS England National CSOC assesses that as a proof-of-concept exploit is available, exploitation is highly likely.
Axios has released a security update to address a critical vulnerability in the Axios HTTP client library. Successful exploitation could allow an attacker to escalate prototype pollution in third‑party dependencies into remote code execution or full cloud environment compromise, including credential theft from cloud metadata services.
Affected organisations are strongly encouraged to review the Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain advisory and upgrade to Axios version 1.15.0 or later as soon as possible
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0, the Axios library is vulnerable to a specific "Gadget" attack chain that allows Prototype Pollution in any third-party dependency to be escalated into Remote Code Execution (RCE) or Full Cloud Compromise (via AWS IMDSv2 bypass). This vulnerability is fixed in 1.15.0.
Last edited: 14 April 2026 3:06 pm
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
