logo

LMDeploy CVE-2026-33626 Flaw Exploited Within 13 Hours of Disclosure

ID: 1c2cb21e-ab44-53fa-a681-98a94fc98579

STIX ID: report--1c2cb21e-ab44-53fa-a681-98a94fc98579

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-04-24

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

A high-severity SSRF in LMDeploy (CVE-2026-33626, CVSS 7.5) was exploited in the wild within ~13 hours of disclosure to access cloud metadata, internal services, and perform port scans (attacker IP 103.116.72.119 observed), while separate active exploits target two WordPress plugins (CVE-2026-0740 and CVE-2026-3844) enabling RCE, and a widespread campaign probed and targeted internet-exposed Modbus PLCs across 70 countries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.