logo

175,000 Exposed Ollama Hosts Enable Code Execution and External System Access

ID: 5a0e641a-c2da-50fe-93f6-f168db1c9b66

STIX ID: report--5a0e641a-c2da-50fe-93f6-f168db1c9b66

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-01-30

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Researchers discovered roughly 175,000 publicly reachable Ollama servers caused by simple misconfiguration (binding to 0.0.0.0), creating widespread risk of remote code execution and unauthorized access; nearly half of hosts support tool-calling (38% with text completion and tool execution), many have vision and reasoning capabilities, and a monoculture of identical model formats amplifies the potential blast radius across 130 countries and 4,032 ASNs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.