LMDeploy CVE-2026-33626 Flaw Exploited Within 13 Hours of Disclosure
ID: 1c2cb21e-ab44-53fa-a681-98a94fc98579
STIX ID: report--1c2cb21e-ab44-53fa-a681-98a94fc98579
Feed Name: The Hacker News
Threat Score
A high-severity SSRF in LMDeploy (CVE-2026-33626, CVSS 7.5) was exploited in the wild within ~13 hours of disclosure to access cloud metadata, internal services, and perform port scans (attacker IP 103.116.72.119 observed), while separate active exploits target two WordPress plugins (CVE-2026-0740 and CVE-2026-3844) enabling RCE, and a widespread campaign probed and targeted internet-exposed Modbus PLCs across 70 countries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
