Cwe-918 - Server-Side Request Forgery (ssrf) - Cwe

Threat entity extracted from intelligence sources

Frequency
80
occurrences
First Seen
May 7, 2026
Last Seen
August 6, 2026

Cwe-918 - Server-Side Request Forgery (ssrf) is a cwe tracked by ThreatCluster, appearing in 41 threat clusters built from 80 intelligence report mentions.

Cwe-918 - Server-Side Request Forgery (ssrf) is a cwe tracked across 41 threat clusters and 80 intelligence report mentions on ThreatCluster. First observed May 7, 2026; most recent activity August 6, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • SUSE Nodejs22 Important Security Fix - Advisory 2026-3521 — Linuxsecurity · August 6, 2026
  • OpenAI's AI models teamed up to hack their way online. Then Meta admitted a breach of its own — Insurancebusinessmag · August 6, 2026
  • AI Agent Framework Flaws Enabled Unauthorized Tool Use and Remote Code Execution — Mallory.Ai · August 6, 2026
  • Hephaestus Automated Attack Framework Targeting Government And Educational Institutions In Indonesia — oasis-security.io · August 6, 2026
  • CVE-2026-15409 — nvd.nist.gov · August 5, 2026
  • CVE-2026-65924 — nvd.nist.gov · July 30, 2026
  • CVE-2026-65923 — nvd.nist.gov · July 30, 2026
  • BleepingComputer: OpenAI models used Artifactory zero-days to escape to the internet — www.bleepingcomputer.com · July 30, 2026

Frequently asked questions

What is Cwe-918 - Server-Side Request Forgery (ssrf)?

Cwe-918 - Server-Side Request Forgery (ssrf) is a cwe tracked by ThreatCluster, appearing in 41 threat clusters built from 80 intelligence report mentions.

Is Cwe-918 - Server-Side Request Forgery (ssrf) still active?

The most recent intelligence report mentioning Cwe-918 - Server-Side Request Forgery (ssrf) on ThreatCluster is dated August 6, 2026. Activity was first observed May 7, 2026, giving a tracked span from then to August 6, 2026.

What is Cwe-918 - Server-Side Request Forgery (ssrf) associated with?

Across ThreatCluster reporting, Cwe-918 - Server-Side Request Forgery (ssrf) most frequently co-occurs with Shadow-aether-015, ShinyHunters, Authentication Bypass, Botnet, Brute Force, among 12 tracked related entities.

What are the latest developments involving Cwe-918 - Server-Side Request Forgery (ssrf)?

The most significant recent cluster is “Critical SonicWall SMA1000 Vulnerabilities Under Active Exploitation” (44 articles · Updated July 15, 2026). Cwe-918 - Server-Side Request Forgery (ssrf) appears across 41 threat clusters in total, listed above with sources.

How much reporting does ThreatCluster have on Cwe-918 - Server-Side Request Forgery (ssrf)?

Cwe-918 - Server-Side Request Forgery (ssrf) appears in 80 intelligence report mentions across 41 deduplicated threat clusters, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown