New LMDeploy Vulnerability Exploited in the Wild Just 12 Hours After Public Advisory
ID: 525285a2-a73e-56e1-8a2f-0c6ef3b3c1bc
STIX ID: report--525285a2-a73e-56e1-8a2f-0c6ef3b3c1bc
Feed Name: Cyber Press
A Server-Side Request Forgery (SSRF) vulnerability in LMDeploy (CVE-2026-33626) was weaponized in the wild within 12 hours and 31 minutes of disclosure; attackers used the vulnerable vision-image loader to probe AWS Instance Metadata (169.254.169.254), localhost services (Redis 6379, MySQL 3306), and an unauthenticated /distserve admin endpoint, and confirmed blind SSRF via an out-of-band callback domain. The patched LMDeploy v0.12.3 blocks link-local, loopback, and private ranges; operators are urged to upgrade, enforce IMDSv2, and restrict outbound egress for inference nodes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
