Open Redirect is a web vulnerability where an application accepts a user-supplied URL and redirects the user to another site, often without proper validation.
Open Redirect is a vulnerability tracked across 4 threat clusters and 5 intelligence report mentions on ThreatCluster. First observed November 13, 2025; most recent activity August 2, 2026.
Open Redirect is a web vulnerability where an application accepts a user-supplied URL and redirects the user to another site, often without proper validation. This can enable phishing, credential theft, or drive-by malware by steering users to attacker-controlled domains, and it remains a notable risk across consumer and enterprise software due to its ease of exploitation and broad prevalence.
SAP has released critical security patches addressing a code injection vulnerability in SAP Solution Manager (ST 720), tracked as CVE-2025-42880. This vulnerability is rated Critical and affects users of the affected…
Fedora has released updates for LemonLDAP-ng versions 2.23.1 and 2.23.2 to address CVE-2026-12804, which is an Open Redirect vulnerability. This flaw allows attackers to manipulate URLs in the SAML Common Domain Cookie…
Snyk conducted 300 vulnerability scans to evaluate the repeatability of LLM security reviews on identical code and prompts. The results showed that while reference-matched findings were stable, extra-model reports…
Researchers from the DistriNet Research Unit at KU Leuven have found that many newly released devices, including cars, contain outdated web browsers that lack essential security updates. These embedded browsers can be…
Open Redirect is a web vulnerability where an application accepts a user-supplied URL and redirects the user to another site, often without proper validation.
The most recent intelligence report mentioning Open Redirect on ThreatCluster is dated August 2, 2026. Activity was first observed November 13, 2025, giving a tracked span from then to August 2, 2026.
Across ThreatCluster reporting, Open Redirect most frequently co-occurs with Code Injection, Command Injection, Phishing, Privilege Escalation, Sql Injection, among 12 tracked related entities.
The most significant recent cluster is “Critical Code Injection Vulnerability in SAP Solution Manager Disclosed” (7 articles · Updated December 9, 2025). Open Redirect appears across 4 threat clusters in total, listed above with sources.
Open Redirect appears in 5 intelligence report mentions across 4 deduplicated threat clusters, aggregated from 17,000+ monitored sources.