logo

CVE-2026-33626: How attackers exploited LMDeploy LLM Inference Engines in 12 hours

ID: a3c59e8f-cc4c-5b3c-8feb-243c9fa01130

STIX ID: report--a3c59e8f-cc4c-5b3c-8feb-243c9fa01130

Feed Name: Sysdig Blog

Threat Score
78/100

Date Published: 2026-04-22

Date Updated: 2026-05-01

...
...

Sysdig observed active exploitation of CVE-2026-33626, an SSRF in LMDeploy, within 12 hours and 31 minutes of a GHSA publication; an attacker used the image_url vision-LLM primitive to fetch AWS IMDS, probe loopback services (Redis, MySQL, admin HTTP), and validate egress via an OOB DNS callback. The report includes a detailed exploitation timeline, target URLs and source IP IOC (103.116.72.119), detection recommendations (application and host-layer alerts, Falco rules), and mitigations (upgrade to v0.12.3, enforce IMDSv2, restrict egress, rotate role credentials).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.