Server-side request forgery vulnerabilities
Server-side request forgery tricks a server into making requests on the attacker’s behalf — reaching internal services, cloud metadata endpoints, or admin APIs that are unreachable from outside. In cloud environments SSRF is a credential-theft primitive, and it chains naturally with other bugs into full compromise.
Classification is assigned by the CSIRTS enrichment pipeline from the advisory text. The list below shows the latest advisories tagged server-side request forgery, newest first, across national CERTs, vendor PSIRTs and vulnerability databases — exploited marks CVEs in the CISA KEV catalog.
Latest server-side request forgery advisories
[NEW] [medium] wget: Vulnerability allows bypassing of security measures
CVE-2026-18952 - Missing Input Validation in OpenSearch Security Analytics Plugin
CVE-2026-15643 - AWS HealthLake MCP Server SSRF via Unvalidated Pagination URL
CVE-2026-15746 - Credential disclosure in Strands Agents Tools elasticsearch_memory tool
[NEW] [high] n8n: Multiple vulnerabilities
[NEW] [high] Splunk Splunk Enterprise: Multiple vulnerabilities
MLflow security advisory (AV26-832)
Cisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise Server-Side Request Forgery Vulnerability
CISA Adds One Known Exploited Vulnerability to Catalog
Multiple vulnerabilities in Synacor Zimbra Collaboration (August 19, 2026)
CVE-2026-64849: MLflow Server-Side Request Forgery Vulnerability
USN-8641-1: .NET vulnerabilities
[NEW] [medium] JetBrains IntelliJ IDEA: Multiple vulnerabilities
Apache Allura vulnerable to server-side request forgery
DSA-6449-1 swift - security update
CVE-2026-64849: MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/
GHSA-7gwp-5pfp-969j: MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
[NEW] [high] WP Royal Royal Elementor Addons: Multiple vulnerabilities
[NEW] [high] Apache Camel: Multiple vulnerabilities
USN-8638-1: Axios vulnerabilities
[NEW] [high] Commvault Backup & Recovery: Multiple Vulnerabilities
Server-Side Request Forgery (SSRF)
DSA-6435-1 spip - security update
Johnson Controls C-CURE 9000 and Victor application server (Update A)
[UPDATE] [high] Apache Tika: Vulnerability allows information gain or manipulation
CVE-2026-70326: Microsoft SharePoint Server Elevation of Privilege Vulnerability
CVE-2026-69502: Azure SQL Database Elevation of Privilege Vulnerability
CVE-2026-58612: PowerShell Information Disclosure Vulnerability
CVE-2026-58639: Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-69855: Microsoft Copilot in Azure Information Disclosure Vulnerability
CVE-2026-70324: Microsoft SharePoint Elevation of Privilege Vulnerability
CVE-2026-65801: Microsoft Exchange Online Elevation of Privilege Vulnerability
CVE-2026-69543: Azure Virtual Machines Elevation of Privilege Vulnerability
CVE-2026-70367: Stunnel: ssrf bypass in stunnel socks proxy via ipv4-mapped ipv6 loopback and unspecified addresses allows access to loopback-only services
CVE-2026-66800: Azure Data Factory Information Disclosure Vulnerability
CVE-2026-69851: Microsoft Entra ID Elevation of Privilege Vulnerability
CVE-2026-65813: Microsoft Exchange Server Elevation of Privilege Vulnerability
Multiple vulnerabilities in SPIP (August 11, 2026)
Multiple vulnerabilities in Roundcube (August 10, 2026)
DSA-6427-1 wordpress - security update
Multiple vulnerabilities in WordPress (August 07, 2026)
NCSC-2026-0278 [1.00] [M/H] Vulnerabilities patched in Adobe Campaign Classic
CVE-2025-69299: WordPress Oxygen theme <= 6.0.8 - Server Side Request Forgery (SSRF) vulnerability
CVE-2026-48522: PyJWKClient: missing scheme allowlist enables SSRF + token forgery via file://, ftp://, data: schemes
CVE-2025-59775: Apache HTTP Server: NTLM Leakage on Windows through UNC SSRF
CVE-2026-3632: Libsoup: libsoup: http smuggling and server-side request forgery via malformed hostnames
CVE-2026-48144: Apache Thrift: c_glib TLS Client Missing Hostname Verification
Multiple vulnerabilities in LibreNMS (August 4, 2026)
NCSC-2026-0272 [1.00] [M/H] Vulnerabilities patched in JFrog Artifactory
Other vulnerability classes
New server-side request forgery advisories, in your inbox. The daily briefing covers every advisory in this class the morning after it lands. Subscribe free — one email every morning after 06:00 UTC, one-click unsubscribe. Tracking specific products instead? Watch them from any product page and get alerted only when they ship a new advisory.