Cwe-918 - Server-Side Request Forgery (ssrf) is a cwe tracked by ThreatCluster, appearing in 41 threat clusters built from 80 intelligence report mentions.
Cwe-918 - Server-Side Request Forgery (ssrf) is a cwe tracked across 41 threat clusters and 80 intelligence report mentions on ThreatCluster. First observed May 7, 2026; most recent activity August 6, 2026.
SonicWall has reported two critical vulnerabilities, CVE-2026-15409 and CVE-2026-15410, affecting its SMA1000 Series appliances, which are currently being actively exploited. The first vulnerability, CVE-2026-15409, is…
Cisco has disclosed a critical authentication bypass vulnerability, CVE-2026-20182, affecting its Catalyst SD-WAN Controller and Manager. This flaw allows unauthenticated remote attackers to bypass authentication and…
Active exploitation of two critical vulnerabilities has been reported: CVE-2026-20230 in Cisco Unified CM and CVE-2026-20971 in Samsung KNOX. The Cisco flaw, a server-side request forgery (SSRF), poses an immediate…
A pre-authentication remote code execution (RCE) vulnerability, CVE-2026-35273, was discovered in Oracle PeopleSoft PeopleTools, affecting versions 8.61 and 8.62. The vulnerability allows unauthenticated attackers to…
In July 2026, several critical vulnerabilities were exploited, impacting SonicWall SMA1000 appliances and SharePoint servers. Two zero-day vulnerabilities, CVE-2026-15409 and CVE-2026-15410, were discovered in SonicWall…
Recent updates to RoundcubeMail for Fedora 43 and 44 revealed critical vulnerabilities, including SQL injection and cross-site scripting (XSS) issues. CVE-2026-48842 details a pre-auth SQL injection in the…
Apache Syncope has released critical updates to address six vulnerabilities, including remote code execution (RCE) and SQL injection flaws. The vulnerabilities affect versions 4.1, 4.0, and 3.0 of the Syncope identity…
Fluentd v1.19.3 addresses multiple vulnerabilities, including a critical RCE flaw tracked as CVE-2026-44024. These vulnerabilities can allow unauthenticated remote attackers to execute arbitrary code, access sensitive…
Cisco has released security advisories addressing multiple high-severity vulnerabilities in its Unity Connection product. The most critical flaws allow authenticated attackers to inject and execute malicious code…
The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-45659, a remote code execution vulnerability in Microsoft SharePoint, to its Known Exploited Vulnerabilities catalog due to active…
Cwe-918 - Server-Side Request Forgery (ssrf) is a cwe tracked by ThreatCluster, appearing in 41 threat clusters built from 80 intelligence report mentions.
The most recent intelligence report mentioning Cwe-918 - Server-Side Request Forgery (ssrf) on ThreatCluster is dated August 6, 2026. Activity was first observed May 7, 2026, giving a tracked span from then to August 6, 2026.
Across ThreatCluster reporting, Cwe-918 - Server-Side Request Forgery (ssrf) most frequently co-occurs with Shadow-aether-015, ShinyHunters, Authentication Bypass, Botnet, Brute Force, among 12 tracked related entities.
The most significant recent cluster is “Critical SonicWall SMA1000 Vulnerabilities Under Active Exploitation” (44 articles · Updated July 15, 2026). Cwe-918 - Server-Side Request Forgery (ssrf) appears across 41 threat clusters in total, listed above with sources.
Cwe-918 - Server-Side Request Forgery (ssrf) appears in 80 intelligence report mentions across 41 deduplicated threat clusters, aggregated from 17,000+ monitored sources.