Skip to content
Product
Use it
Threat intelligence API
Free key, 70+ endpoints, OpenAPI. The product.
Get started
Pick your stack, make your first call.
Live feed
The console: incidents, filters, entities, search.
Recipes
Runnable examples for the free key.
Free feeds
RSS, ransomware feed, IOC blocklist, MISP — no key.
CLI & agents
tc from a terminal; agent keys with scoped budgets.
The data
Incident records
900 articles a day become ~70 scored incidents.
Dark web
First-party leak-site collection: victims, groups, markets.
Validated IOCs
Indicators with a false-positive gate; STIX, MISP, CSV.
Vulnerabilities
CVEs with EPSS, KEV and exploit status.
Entity graph
Actors, malware, CVEs, companies — pivotable.
For teams
For service providers
Per-client feeds, alerts and branded digests.
Use cases
How teams and builders use the corpus.
About ThreatCluster
What it is and how it is built.
Pricing
Docs
Reference
OpenAPI (Swagger)
Every endpoint, parameter and response model.
ReDoc
The same reference, long-form.
Examples on GitHub
curl, Python and Node quickstarts; daily spec snapshot.
Guides
Quickstart & plans
Key, scopes, budgets, tiers.
Integrations
Splunk, Sentinel, Elastic, agents and terminals, step by step
Export formats
STIX 2.1, MISP, CSV, text.
CLI setup
Install, log in, wire an agent.
No results found
Sign in
Get a free key
No results found
Product
Threat intelligence API
Get started
Live feed
Recipes
Free feeds
CLI & agents
The data
Incident records
Dark web
Validated IOCs
Vulnerabilities
Entity graph
For teams
For service providers
Use cases
About ThreatCluster
Docs
OpenAPI (Swagger)
ReDoc
Examples on GitHub
Quickstart & plans
Integrations
Export formats
CLI setup
Pricing
Contact
Get a free key
Sign in
Back
CWE-918 - Server-Side Request Forgery (ssrf)
CWE Weakness
Threat entity extracted from intelligence sources
Sep 25: 3 mentions
Sep 26: 2 mentions
Sep 27: 2 mentions
Sep 28: 2 mentions
Sep 29: 0 mentions
Sep 30: 1 mention
Oct 1: 2 mentions
Sep 25
Sep 28
Oct 1
Entities
›
cwe
›
CWE-918 - Server-Side Request Forgery (ssrf)
Frequency
178
occurrences
First Seen
May 7, 2026
Last Seen
October 1, 2026
API
Overview
Recent Events
Profile
Profile
MITRE ATT&CK
1 / 2
Threat Actors
Shadow-aether-015
ShinyHunters
INC Ransomware
Qilin
Malware
Knuckleball
Sphinx
Tools
Python
LiteLLM
Hugging Face
Orangetail
Rootrun
Nginx
Docker
OneDrive
CVEs
CVE-2026-83548
CVE-2026-83549
CVE-2026-20230
CVE-2026-15409
CVE-2026-15410
CVE-2026-35273
CVE-2026-48710
CVE-2026-49869
Regions
United States
South Korea
Switzerland
Russia
North Korea
Sectors
Government
Healthcare
Manufacturing
Financial
-
REC
Recon
No techniques detected
-
RD
Resource Dev
No techniques detected
3
IA
Initial Access
T1190 - Exploit Public-Facing Application
T1566 - Phishing
T1078 - Valid Accounts
4
EX
Execution
T1059 - Command and Scripting Interpreter
T1203 - Exploitation for Client Execution
T1047 - Windows Management Instrumentation
T1053 - Scheduled Task/Job
3
PE
Persistence
T1505.003 - Web Shell
T1574 - Hijack Execution Flow
T1136 - Create Account
1
PE
Priv Esc
T1068 - Exploitation for Privilege Escalation
-
DE
Defense Evasion
No techniques detected
2
CA
Cred Access
T1003 - OS Credential Dumping
T1110 - Brute Force
-
DI
Discovery
No techniques detected
1
LM
Lateral Mov
T1021 - Remote Services
-
CO
Collection
No techniques detected
1
C2
C2
T1071 - Application Layer Protocol
2
EX
Exfil
T1041 - Exfiltration Over C2 Channel
T1567 - Exfiltration Over Web Service
1
IM
Impact
T1486 - Data Encrypted for Impact
19
techniques detected across
9
tactics
Related Clusters (50)
Critical Zero-Day Vulnerability in Cisco ISE Under Active Exploitation
Sep 16
·
58 sources
89
Critical SonicWall SMA1000 Vulnerabilities Under Active Exploitation
Jul 15
·
42 sources
87
Critical Zero-Day Vulnerability CVE-2026-20182 Exploited in Cisco SD-WAN Systems
May 14
·
94 sources
87
Critical Exploitation of Cisco CM and Samsung KNOX Vulnerabilities
Jun 23
·
4 sources
86
SonicWall SMA1000 Faces Critical Zero-Day Exploitation
Sep 2
·
123 sources
81
Critical RCE Vulnerability in Oracle PeopleSoft Exploited by SHADOW-AETHER-015
Jun 18
·
5 sources
78
Multiple Critical Vulnerabilities Exploited in SonicWall and SharePoint Systems
Jul 28
·
1 sources
75
Multiple CVEs Disclosed on September 8, 2026, Affecting Microsoft Products
Sep 8
·
927 sources
74
Cisco Unity Connection Vulnerabilities Enable Code Execution and SSRF Attacks
May 7
·
3 sources
74
Critical SQL Injection and XSS Vulnerabilities in RoundcubeMail Affect Fedora Users
Jun 4
·
2 sources
74
Critical Vulnerabilities in Fluentd Enable Remote Code Execution and SSRF
Jul 1
·
3 sources
74
Apache Syncope Vulnerabilities Enable Remote Code Execution and Privilege Escalation
Jul 24
·
2 sources
74
Cisco Confirms Active Exploitation of Unified CM Vulnerability CVE-2026-20230
Jul 2
·
2 sources
73
Active Exploitation of MLflow SSRF Vulnerability CVE-2026-64849
Aug 18
·
7 sources
73
Critical Vulnerabilities in Exposed MCP Servers Threaten Sensitive Data
Jul 29
·
2 sources
73
Critical SSRF Vulnerability in Cisco Unified CM Exposes Enterprises to Root Access
Jun 4
·
6 sources
72
Critical Vulnerabilities in React and Next.js Require Immediate Updates
May 8
·
5 sources
72
CISA Adds Multiple Exploited Flaws in AI and Networking Tools to KEV Catalog
Sep 13
·
3 sources
72
Critical Vulnerabilities in Adobe Connect Require Immediate Patching
Sep 23
·
3 sources
72
High-Risk SSRF Vulnerabilities in AzuraCast Webhook and Remote Relay Features
4d ago
·
1 sources
71
Critical Vulnerabilities in SUSE python-PyJWT Lead to DoS and SSRF Risks
Jun 25
·
3 sources
71
Critical SearchLeak Vulnerability in Microsoft 365 Copilot Exposes Sensitive Data
Jun 15
·
25 sources
71
Critical Security Flaws Found in SUSE Node.js Versions 22 and 24
Aug 6
·
2 sources
71
Critical Denial of Service and Auth Bypass Vulnerabilities in Fedora Erlang
Jul 19
·
2 sources
71
Critical SSRF Vulnerability in MLflow Actively Exploited, CISA Issues Warning
Aug 21
·
2 sources
70
Red Hat Kubernetes SSRF Vulnerability Exposes Internal Services to Attackers
Aug 20
·
2 sources
69
Critical RCE Vulnerability in BeyondTrust Software Requires Immediate Patching
Feb 9
·
860 sources
67
SSRF Vulnerability in Sentry MCP Server Exposes Security Risks
Aug 28
·
2 sources
65
High-Risk SSRF Vulnerability in Privoce VoceChat Server Disclosed
3d ago
·
1 sources
65
Ransomware Fuels Surge in Global Cyberattacks
Feb 12
·
1498 sources
64
CVE-2024 and CVE-2023 Exploits Reported
Sep 13
·
3 sources
64
Critical SSRF Vulnerability in GitHub Enterprise Server (CVE-2026-77987)
Sep 24
·
2 sources
61
Critical Vulnerabilities Patched in Check Point, Kaspersky, and Tanium Products
Sep 18
·
4 sources
61
Debian Swift Security Flaws Prompt Urgent Updates
Aug 20
·
2 sources
61
CVE-2026-69855: Microsoft Copilot SSRF Vulnerability Disclosed
Aug 22
·
1 sources
60
CVE-2026-92602: TDuckCloud Survey Form Vulnerability Exposes User Data
Sep 17
·
1 sources
59
Critical SSRF Vulnerability in CordysCRM Exposed
6d ago
·
1 sources
58
Wget Vulnerability Allows Server-Side Request Forgery via FTP PASV Response
Jul 20
·
2 sources
58
Starlette Vulnerability Allows Path Injection via Host Header
May 27
·
0 sources
58
Multiple Vulnerabilities Found in Azuracast Before Version 0.23.8
4d ago
·
0 sources
57
OpenAI Launches GPT-5.4-Cyber Amidst Cybersecurity Arms Race
Apr 14
·
1065 sources
52
Chained Risks in AI Applications Expose Vulnerabilities
Aug 27
·
2 sources
52
AWS Incident Response Guide Highlights Cloud Security Threats
Sep 4
·
2 sources
43
Snyk VulnBench JS 1.0 Reveals Inconsistencies in LLM Security Findings
Jun 29
·
2 sources
40
Critical RCE Vulnerability in BeyondTrust Remote Support and PRA
Feb 7
·
229 sources
30
SSRF Vulnerability Disclosed in Nextcloud Notifications App
4h ago
·
2 sources
28
Microsoft Updates Dynamics 365 Bug Bounty Program
Sep 17
·
1 sources
28
Microsoft Releases AntiSSRF Library to Combat Server-Side Request Forgery
Jun 19
·
2 sources
28
Microsoft Launches Dusseldorf Open-Source OAST Platform for Vulnerability Detection
Jul 20
·
2 sources
28
RamziRange10 Exploit Enhances Vulnerability Testing Tools
Sep 14
·
2 sources
27
Prev
1 / 10
Next
Related Articles (50)
HackerOne Bug Bounty Disclosure: ssrf-via-user-controlled-push-proxyserver-in-notifications-push-registration
Redpacketsecurity
·
4h ago
Google GTIG finds AI accelerating vulnerability discovery across enterprise and critical ...
Industrialcyber.Co
·
11h ago
HackerOne Bug Bounty Disclosure: ssrf-via-user-controlled-push-proxyserver-in-notifications-push-registration
Redpacketsecurity
·
1d ago
2026 08 06 Ssrf Vulnerability In Vocechat Server V0520
is.yuum.me
·
3d ago
CVE Alert: CVE-2026-100893 – Privoce
Redpacketsecurity
·
3d ago
Azuracast Before 0.23.8 Ssrf And Local File Read Via Remote Playlist
www.vulncheck.com
·
4d ago
CVE Alert: CVE-2026-100849 – AzuraCast
Redpacketsecurity
·
4d ago
Rapid7 Vulnerability & Exploit Database
Rapid7
·
4d ago
The August 2026 Security Update Review
www.zerodayinitiative.com
·
5d ago
Security Bulletin node/7288641
www.ibm.com
·
6d ago
GitHub Security Advisory GHSA-fg6q-pfj7-fghw
github.com
·
6d ago
CVE-2026-76900: CordysCRM SSRF Vulnerability
Sentinelone
·
6d ago
Critical CVE-2026-77987 affects GitHub Enterprise Server, allowing attackers to exploit an ...
Ccb.Belgium.Be
·
Sep 24
Critical CVE-2026-77987 affects GitHub Enterprise Server, allowing attackers to exploit an ...
Ccb.Belgium.Be
·
Sep 24
Adobe Patches Critical Flaws in Connect, AEM Forms
Securityweek
·
Sep 23
HR Software Not Updated for Three Months: How the FBI Just Got Hacked
Emeraldbook
·
Sep 23
Adobe Patch Day 2026-09-22: 10 critical vulnerabilities amid 29 CVEs
Feedly
·
Sep 23
Plugin4Shell Bypasses SHA Pinning Across All Four Major AI Coding Agents
Forkast.News
·
Sep 18
Check Point, Kaspersky, Tanium Patch Product Vulnerabilities
Securityweek
·
Sep 18
GHSA W5pf Xwjh Vr5v
github.com
·
Sep 18
Bounty Dynamics
www.microsoft.com
·
Sep 17
Squashing vulnerabilities: Microsoft udpates Dynamics 365 bug bounty program
Msdynamicsworld
·
Sep 17
lazyrecon exploit
Sploitus
·
Sep 17
Cisco Security Advisory: Cisco Identity Services Engine Vulnerabilities
Sec.Cloudapps.Cisco
·
Sep 17
Tduck Survey Form Through 5.3 Server Side Request Forgery Via Unvalidated Webhook Url
www.vulncheck.com
·
Sep 17
40
github.com
·
Sep 17
[vulnfeed] 34 critical CVEs — 2026-09-16 20:00 UTC
Buttondown
·
Sep 17
CVE Alert: CVE-2026-92602 – TDuckCloud – tduck-survey
Redpacketsecurity
·
Sep 17
Etr Critical Sonicwall Sma1000 Vulnerabilities Cve 2026 83548 Cve 2026 83549 Exploited In The Wild
www.rapid7.com
·
Sep 15
CVE Alert: CVE-2026-13275 – IBM
Redpacketsecurity
·
Sep 15
RamziRange10 exploit
Sploitus
·
Sep 14
The State Of Ai For Security Measuring What Matters Most For Building Trust
aws.amazon.com
·
Sep 14
How SonicWall SMA1000's First Zero
Tech.Yahoo
·
Sep 13
The Chain That Opened the Crisis: How SonicWall SMA1000's First Zero
Forkast.News
·
Sep 13
CVE-2023
Sploitus
·
Sep 12
Mise A Jour Critique De Securite Sortie De SPIP 4 4 18
blog.spip.net
·
Sep 12
Exposed Server Reveals Automated Extortion Pipeline | Information & Data Manager
Idm.Au
·
Sep 11
Known Exploited Vulnerabilities Catalog
www.cisa.gov
·
Sep 11
CISA KEV Catalog Adds Seven Exploited Flaws Across AI Stacks and VPNs
Cybersecurity-Insiders
·
Sep 10
RamziRange3 exploit
Sploitus
·
Sep 10
OWASP Top 10
www.techtarget.com
·
Sep 9
CVE-2026
Api.Msrc.Microsoft
·
Sep 9
Microsoft Patch Tuesday September 2026 Security Update Review
blog.qualys.com
·
Sep 8
September 2026
support.sap.com
·
Sep 8
Onapsis says
onapsis.com
·
Sep 8
September 2026 security updates
support.sap.com
·
Sep 8
Xenforo Ssrf Via Paypal Rest Webhook Handler
www.vulncheck.com
·
Sep 8
CVE-2026
Api.Msrc.Microsoft
·
Sep 8
CVE-2026
Api.Msrc.Microsoft
·
Sep 8
CVE-2026
Api.Msrc.Microsoft
·
Sep 8
Prev
1 / 10
Next
Related Entities
Shadow-aether-015
ShinyHunters
Zero-day Exploit
Data Breach
Sql Injection
Server-Side Request Forgery
Server-Side Request Forgery (ssrf)
Ransomware
Cross-Site Scripting (xss)
Denial of Service
Remote Code Execution
Phishing