Cwe-918 - Server-Side Request Forgery (ssrf) - Cwe

Threat entity extracted from intelligence sources

Frequency
99
occurrences
First Seen
May 7, 2026
Last Seen
August 26, 2026

Related Threat Clusters

Recent Intelligence Reports

  • NLTK Mass Disclosure — 4 CVEs, Peak 9.8 (Allowlisted Pickle RCE) ThreatAft — Cybersecurity Intelligence / 12h A mass disclosure of four CVEs across versions before 3.10.3 just dropped, with CVE-2026-79657 leading at CVSS 9.8 — an unsafe pickle deserialization vulnerability where allowlisted pickle loaders trust entire module namespaces, allowing arbitrary code execution via crafted model files. CVSS 9.8 — Critical pickle deserialization RCE — CVE-2026-79657 allows attackers to execute arbitrary — threataft.com · August 26, 2026
  • CVE-2026-69855 - Microsoft Copilot in Azure Information Disclosure Vulnerability Latest Vulnerabilities / 1d CVE ID : CVE-2026-69855 Published : Aug. 20, 2026, 10:18 p.m. 3 hours, 39 minutes ago Description : Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network. Severity: 7.7 HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... — cvefeed.io · August 22, 2026
  • Threataft Blog News Aug 21, 2026 CVE-2026-65801: Microsoft Exchange Online SSRF - CVSS 10 threataft.com Open source — threataft.com · August 21, 2026
  • Cvefeed High Severity Advisories Aug 21, 2026 CVE-2026-69502 - Azure SQL Database Elevation of Privilege Vulnerability cvefeed.io Open source — cvefeed.io · August 21, 2026
  • CVE-2026-69855 - Exploits & Severity — Feedly · August 21, 2026
  • Microsoft fixes critical CVSS 10 cloud flaws, including Exchange Online SSRF — Mallory.Ai · August 21, 2026
  • Falla crítica en MLflow bajo explotación activa — Ciberseguridadlatam · August 21, 2026
  • Untitled report — Ciberseguridadlatam · August 21, 2026

CVSS v3.1 Breakdown