Skip to content
Product
Use it
Threat intelligence API
Free key, 70+ endpoints, OpenAPI. The product.
Get started
Pick your stack, make your first call.
Live feed
The console: incidents, filters, entities, search.
Recipes
Runnable examples for the free key.
Free feeds
RSS, ransomware feed, IOC blocklist, MISP — no key.
CLI & agents
tc from a terminal; agent keys with scoped budgets.
The data
Incident records
900 articles a day become ~70 scored incidents.
Dark web
First-party leak-site collection: victims, groups, markets.
Validated IOCs
Indicators with a false-positive gate; STIX, MISP, CSV.
Vulnerabilities
CVEs with EPSS, KEV and exploit status.
Entity graph
Actors, malware, CVEs, companies — pivotable.
For teams
For service providers
Per-client feeds, alerts and branded digests.
Use cases
How teams and builders use the corpus.
About ThreatCluster
What it is and how it is built.
Pricing
Docs
Reference
OpenAPI (Swagger)
Every endpoint, parameter and response model.
ReDoc
The same reference, long-form.
Examples on GitHub
curl, Python and Node quickstarts; daily spec snapshot.
Guides
Quickstart & plans
Key, scopes, budgets, tiers.
Integrations
Splunk, Sentinel, Elastic, agents and terminals, step by step
Export formats
STIX 2.1, MISP, CSV, text.
CLI setup
Install, log in, wire an agent.
No results found
Sign in
Get a free key
No results found
Product
Threat intelligence API
Get started
Live feed
Recipes
Free feeds
CLI & agents
The data
Incident records
Dark web
Validated IOCs
Vulnerabilities
Entity graph
For teams
For service providers
Use cases
About ThreatCluster
Docs
OpenAPI (Swagger)
ReDoc
Examples on GitHub
Quickstart & plans
Integrations
Export formats
CLI setup
Pricing
Contact
Get a free key
Sign in
Back
Cwe-918 - Server-Side Request Forgery (ssrf)
CWE Weakness
Threat entity extracted from intelligence sources
Sep 18: 3 mentions
Sep 19: 0 mentions
Sep 20: 0 mentions
Sep 21: 0 mentions
Sep 22: 0 mentions
Sep 23: 3 mentions
Sep 24: 0 mentions
Sep 18
Sep 21
Sep 24
Entities
›
cwe
›
Cwe-918 - Server-Side Request Forgery (ssrf)
Frequency
165
occurrences
First Seen
May 7, 2026
Last Seen
September 23, 2026
API
Overview
Recent Events
Profile
Profile
MITRE ATT&CK
1 / 2
Threat Actors
Shadow-aether-015
ShinyHunters
Qilin
INC Ransomware
Malware
Knuckleball
Sphinx
Tools
LiteLLM
Python
Orangetail
Hugging Face
Nginx
Rootrun
Docker
OneDrive
CVEs
CVE-2026-83548
CVE-2026-83549
CVE-2026-20230
CVE-2026-15409
CVE-2026-15410
CVE-2026-48710
CVE-2026-35273
CVE-2026-42824
Regions
United States
Switzerland
South Korea
North Korea
Iran
Sectors
Government
Healthcare
Manufacturing
Financial
-
REC
Recon
No techniques detected
-
RD
Resource Dev
No techniques detected
3
IA
Initial Access
T1190 - Exploit Public-Facing Application
T1566 - Phishing
T1078 - Valid Accounts
3
EX
Execution
T1059 - Command and Scripting Interpreter
T1203 - Exploitation for Client Execution
T1053 - Scheduled Task/Job
3
PE
Persistence
T1505.003 - Web Shell
T1574 - Hijack Execution Flow
T1136 - Create Account
1
PE
Priv Esc
T1068 - Exploitation for Privilege Escalation
-
DE
Defense Evasion
No techniques detected
2
CA
Cred Access
T1003 - OS Credential Dumping
T1110 - Brute Force
-
DI
Discovery
No techniques detected
1
LM
Lateral Mov
T1021 - Remote Services
-
CO
Collection
No techniques detected
1
C2
C2
T1071 - Application Layer Protocol
2
EX
Exfil
T1567 - Exfiltration Over Web Service
T1041 - Exfiltration Over C2 Channel
1
IM
Impact
T1486 - Data Encrypted for Impact
18
techniques detected across
9
tactics
Related Clusters (50)
Critical Zero-Day Vulnerability in Cisco ISE Under Active Exploitation
Sep 16
·
80 sources
89
Critical SonicWall SMA1000 Vulnerabilities Under Active Exploitation
Jul 15
·
62 sources
87
Critical Zero-Day Vulnerability CVE-2026-20182 Exploited in Cisco SD-WAN Systems
May 14
·
131 sources
87
Critical Exploitation of Cisco CM and Samsung KNOX Vulnerabilities
Jun 23
·
4 sources
86
Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
Aug 12
·
33 sources
81
SonicWall SMA1000 Faces Critical Zero-Day Exploitation
Sep 2
·
50 sources
81
Critical RCE Vulnerability in Oracle PeopleSoft Exploited by SHADOW-AETHER-015
Jun 18
·
5 sources
78
GeoNetwork Vulnerabilities Enable Unauthenticated RCE in Government Systems
Sep 2
·
6 sources
78
Critical OVERPASS Vulnerability in SAP Kernel Requires Immediate Action
Sep 8
·
22 sources
76
Multiple Critical Vulnerabilities Exploited in SonicWall and SharePoint Systems
Jul 28
·
2 sources
75
Critical SQL Injection and XSS Vulnerabilities in RoundcubeMail Affect Fedora Users
Jun 4
·
2 sources
74
Microsoft's Record Patch Tuesday in June 2026 Addresses 206 Vulnerabilities
Jul 1
·
229 sources
74
CISA Adds Seven Exploited Vulnerabilities; IBM Warns of Langflow OSS Flaws
Sep 2
·
32 sources
74
Critical Vulnerabilities in Fluentd Enable Remote Code Execution and SSRF
Jul 1
·
5 sources
74
Apache Syncope Vulnerabilities Enable Remote Code Execution and Privilege Escalation
Jul 24
·
2 sources
74
Multiple CVEs Disclosed on September 8, 2026, Affecting Microsoft Products
Sep 8
·
927 sources
74
Cisco Unity Connection Vulnerabilities Enable Code Execution and SSRF Attacks
May 7
·
7 sources
74
Microsoft September 2026 Patch Tuesday: Record 974 Vulnerabilities Addressed
Sep 8
·
100 sources
73
Active Exploitation of Microsoft SharePoint Flaw CVE-2026-45659 Confirmed
Jul 4
·
2 sources
73
Cisco Confirms Active Exploitation of Unified CM Vulnerability CVE-2026-20230
Jul 2
·
2 sources
73
CISA Warns of Active Exploitation of Oracle WebLogic Vulnerability CVE-2024-21182
Jun 2
·
17 sources
73
Plugin4Shell: Zero-Click RCE Vulnerability in Major AI Coding Agents
6d ago
·
18 sources
73
Active Exploitation of MLflow SSRF Vulnerability CVE-2026-64849
Aug 18
·
8 sources
73
Critical Authentication Bypass Vulnerability in Spring Authorization Server
Jul 18
·
2 sources
73
Critical Vulnerabilities in Exposed MCP Servers Threaten Sensitive Data
Jul 29
·
2 sources
73
Critical Vulnerabilities in Adobe Connect Require Immediate Patching
18h ago
·
3 sources
72
Critical SSRF Vulnerability in Cisco Unified CM Exposes Enterprises to Root Access
Jun 4
·
8 sources
72
CISA Adds Multiple Exploited Flaws in AI and Networking Tools to KEV Catalog
Sep 13
·
8 sources
72
Critical SQL Injection Vulnerability in SPIP CMS Exposed
Sep 12
·
2 sources
72
Critical Vulnerabilities in WordPress Plugins Allow Unauthenticated File Uploads
Aug 20
·
30 sources
72
Critical Vulnerabilities in React and Next.js Require Immediate Updates
May 8
·
10 sources
72
Critical BadHost Vulnerability Exposes AI Applications to Authentication Bypass
May 26
·
16 sources
72
Critical RCE Vulnerabilities Disclosed in NLTK Toolkit
Aug 26
·
2 sources
72
Critical Security Flaws Found in SUSE Node.js Versions 22 and 24
Aug 6
·
2 sources
71
Critical Denial of Service and Auth Bypass Vulnerabilities in Fedora Erlang
Jul 19
·
2 sources
71
Microsoft June 2026 Patch Tuesday: Record 206 Vulnerabilities Addressed
Jun 9
·
57 sources
71
Critical SearchLeak Vulnerability in Microsoft 365 Copilot Exposes Sensitive Data
Jun 15
·
34 sources
71
CoreBreak Vulnerability Exposes AI Agent Frameworks to Unauthorized Tool Use
Aug 7
·
9 sources
71
Critical Vulnerabilities in SUSE python-PyJWT Lead to DoS and SSRF Risks
Jun 25
·
3 sources
71
Nissan Data Breach Exposes Employee Records via Oracle Vulnerability
Jun 29
·
11 sources
70
Critical SSRF Vulnerability in MLflow Actively Exploited, CISA Issues Warning
Aug 21
·
2 sources
70
Critical CVE-2026-69836 in Microsoft Entra ID Exploited in the Wild
Aug 21
·
47 sources
70
AgentForger: New Phishing Attack Creates Autonomous AI Insiders
Jul 23
·
11 sources
70
New Mistic Backdoor Linked to Ransomware Access Broker Activity
Jun 24
·
21 sources
70
Critical SQL Injection Vulnerabilities in SigNoz Exposed
6d ago
·
6 sources
69
Red Hat Kubernetes SSRF Vulnerability Exposes Internal Services to Attackers
Aug 20
·
2 sources
69
Multiple Vulnerabilities in IBM Financial Transaction Manager Exposed
18h ago
·
10 sources
68
New 'PleaseFix' Vulnerabilities Threaten Agentic Browsers with Widespread Attacks
Jul 29
·
11 sources
68
Multiple Vulnerabilities Discovered in Splunk Products Affecting Security Integrity
Aug 20
·
8 sources
68
Critical RCE Vulnerability in BeyondTrust Software Requires Immediate Patching
Feb 9
·
1495 sources
67
Prev
1 / 10
Next
Related Articles (50)
7288641
www.ibm.com
·
8h ago
Adobe Patches Critical Flaws in Connect, AEM Forms
Securityweek
·
15h ago
Adobe Patch Day 2026-09-22: 10 critical vulnerabilities amid 29 CVEs
Feedly
·
1d ago
Plugin4Shell Bypasses SHA Pinning Across All Four Major AI Coding Agents
Forkast.News
·
5d ago
Check Point, Kaspersky, Tanium Patch Product Vulnerabilities
Securityweek
·
5d ago
GHSA W5pf Xwjh Vr5v
github.com
·
6d ago
Bounty Dynamics
www.microsoft.com
·
6d ago
Squashing vulnerabilities: Microsoft udpates Dynamics 365 bug bounty program
Msdynamicsworld
·
6d ago
lazyrecon exploit
Sploitus
·
6d ago
Cisco Security Advisory: Cisco Identity Services Engine Vulnerabilities
Sec.Cloudapps.Cisco
·
Sep 17
Tduck Survey Form Through 5.3 Server Side Request Forgery Via Unvalidated Webhook Url
www.vulncheck.com
·
Sep 17
40
github.com
·
Sep 17
[vulnfeed] 34 critical CVEs — 2026-09-16 20:00 UTC
Buttondown
·
Sep 17
CVE Alert: CVE-2026-92602 – TDuckCloud – tduck-survey
Redpacketsecurity
·
Sep 17
Etr Critical Sonicwall Sma1000 Vulnerabilities Cve 2026 83548 Cve 2026 83549 Exploited In The Wild
www.rapid7.com
·
Sep 15
CVE Alert: CVE-2026-13275 – IBM
Redpacketsecurity
·
Sep 15
RamziRange10 exploit
Sploitus
·
Sep 14
The State Of Ai For Security Measuring What Matters Most For Building Trust
aws.amazon.com
·
Sep 14
How SonicWall SMA1000's First Zero
Tech.Yahoo
·
Sep 13
The Chain That Opened the Crisis: How SonicWall SMA1000's First Zero
Forkast.News
·
Sep 13
CVE-2023
Sploitus
·
Sep 12
Mise A Jour Critique De Securite Sortie De SPIP 4 4 18
blog.spip.net
·
Sep 12
Exposed Server Reveals Automated Extortion Pipeline | Information & Data Manager
Idm.Au
·
Sep 11
Known Exploited Vulnerabilities Catalog
www.cisa.gov
·
Sep 11
CISA KEV Catalog Adds Seven Exploited Flaws Across AI Stacks and VPNs
Cybersecurity-Insiders
·
Sep 10
RamziRange3 exploit
Sploitus
·
Sep 10
OWASP Top 10
www.techtarget.com
·
Sep 9
CVE-2026
Api.Msrc.Microsoft
·
Sep 9
Microsoft Patch Tuesday September 2026 Security Update Review
blog.qualys.com
·
Sep 8
September 2026
support.sap.com
·
Sep 8
Onapsis says
onapsis.com
·
Sep 8
September 2026 security updates
support.sap.com
·
Sep 8
Xenforo Ssrf Via Paypal Rest Webhook Handler
www.vulncheck.com
·
Sep 8
CVE-2026
Api.Msrc.Microsoft
·
Sep 8
CVE-2026
Api.Msrc.Microsoft
·
Sep 8
CVE-2026
Api.Msrc.Microsoft
·
Sep 8
CVE-2026
Api.Msrc.Microsoft
·
Sep 8
September 1, 2026 product notice
www.sonicwall.com
·
Sep 6
CISA Adds 7 Exploited Flaws as Attackers Target AI Infrastructure
Esecurityplanet
·
Sep 4
github.com: GitHub Security Advisory (GHSA-p6qj-p5m7-f62h) external site
github.com
·
Sep 4
AWS publica guía de respuesta a incidentes basada en tres casos reales de compromiso en la nube
Ciberseguridadlatam
·
Sep 4
SonicWall SMA1000 zero-day exploited, CISA orders patches
Cybernews
·
Sep 3
Critical SonicWall SMA 1000 Zero-Day Vulnerabilities (CVE-2026-83548 & CVE-2026-83549)
Triskelelabs
·
Sep 3
SonicWall Warns of Two Actively Exploited SMA1000 Zero-Days, One Rated Maximum Severity
Thecyberexpress
·
Sep 3
SonicWall reports two major security holes under active exploit
Networkworld
·
Sep 3
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
Thehackernews
·
Sep 3
SonicWall SMA1000 Series: Critical Vulnerability Exploited (Sept. 2026)
Borncity
·
Sep 3
SonicWall reports two major security holes under active exploit
Csoonline
·
Sep 2
Remote access Sonicwall SMA1000: Attackers are manipulating internal services
Heise.De
·
Sep 2
Multiple Vulnerabilities in SonicWall SMA1000 Series Appliances Could Allow for Remote Code Execution
Cisecurity
·
Sep 2
Prev
1 / 10
Next
Related Entities
Shadow-aether-015
ShinyHunters
Zero-day Exploit
Data Breach
Sql Injection
Server-Side Request Forgery
Server-Side Request Forgery (ssrf)
Ransomware
Denial of Service
Remote Code Execution
DDoS
Phishing