VU#943094: ONLYOFFICE ownCloud integration plugin contains a Server-Side Request Forgery (SSRF) vulnerability
ONLYOFFICE's ownCloud integration plugin 9.12 has an SSRF flaw (CVE-2026-84282) letting authenticated admins probe internal networks; no patch exists yet.
CERT/CC published VU#943094 for a server-side request forgery in Ascensio System SIA's ONLYOFFICE ownCloud integration plugin version 9.12, tracked as CVE-2026-84282. The /apps/onlyoffice/ajax/settings/address endpoint does not validate the user-supplied document server URL, so an authenticated administrator can make the ownCloud server send arbitrary requests to localhost and internal hosts. Differences in error responses (connection failures vs SSL/TLS errors) let attackers enumerate open and closed TCP ports for internal reconnaissance. The vendor could not be reached, so no official patch is available; CERT recommends disabling the plugin and applying egress filtering until a fix ships.
Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets
Attackers exploit MLflow SSRF CVE-2026-64849 (CVSS 9.3) to steal cloud credentials; CISA added it to KEV; FUXA flaw CVE-2026-25895 is being scanned.
watchTowr observed exploitation of MLflow CVE-2026-64849, an unauthenticated SSRF (CVSS 9.3) affecting versions below 3.15.0, within hours of CVE assignment on August 17, 2026, with attackers abusing model-registry webhooks to reach cloud metadata endpoints and exfiltrate credentials and secrets. CISA added the flaw to its Known Exploited Vulnerabilities catalog on August 19, 2026, with a September 2 patch deadline for federal civilian agencies. VulnCheck reported scanning of FUXA CVE-2026-25895 (missing authentication plus path traversal, CVSS 9.5, versions through 1.2.9) beginning August 18; about 60 FUXA instances are exposed and no RCE payloads have been dropped yet.
[webapps] Linuxfabrik monitoring_plugins_6.0.0 - SSRF
A public proof-of-concept exploit for an SSRF flaw in Linuxfabrik monitoring_plugins 6.0.0 appeared on Exploit-DB.
Exploit-DB listing 52653 discloses a server-side request forgery (SSRF) vulnerability in Linuxfabrik monitoring_plugins version 6.0.0, classified under web applications. A proof-of-concept exploit is publicly available. No CVE identifier or evidence of in-the-wild exploitation is provided in the listing.
[webapps] Nodemailer 9.0.0 - File Read/ SSRF
A public proof-of-concept demonstrates arbitrary file read and SSRF in Nodemailer 9.0.0.
Exploit-DB entry 52654 contains a webapps proof-of-concept for Nodemailer 9.0.0 demonstrating both arbitrary file read and server-side request forgery. Nodemailer is a widely used Node.js email-sending library, so affected deployments could expose local files or internal services. The listing does not include a CVE identifier or evidence of in-the-wild exploitation.
Server-Side Request Forgery (SSRF)
Fortinet discloses a low-severity SSRF in the FortiSIEM GUI allowing authenticated attackers to send requests from targeted devices.
Fortinet PSIRT advisory FG-IR-26-159, revised 2026-08-12, describes a server-side request forgery (CWE-918) in the FortiSIEM GUI, scored CVSSv3 3.4. An authenticated attacker can send HTTP requests originating from the targeted device via specially crafted requests, potentially enabling internal network probing. No CVE identifier or exploitation status is included in the advisory text.
[webapps] Apache Gravitino 1.2.1 - SSRF
Exploit-DB publishes a webapps SSRF proof-of-concept exploit targeting Apache Gravitino 1.2.1.
Exploit-DB entry 52641 documents a server-side request forgery (SSRF) exploit against Apache Gravitino version 1.2.1. The entry is categorized under web applications and provides a working proof of concept for the flaw.
[webapps] Planyo_Online_Reservation_System 3.0 - Arbitrary File Read via SSRF
Exploit demonstrates arbitrary file read via SSRF in Planyo Online Reservation System 3.0.
Exploit-DB entry 52636 documents an arbitrary file read vulnerability in Planyo Online Reservation System version 3.0, reachable through a server-side request forgery condition. The public PoC shows how the web application can be manipulated to fetch and disclose local files. Sites running the vulnerable version could expose sensitive server files.
CVE-2026-57866: Apache Impala: Secrets Exfiltration via SSRF
Apache Impala CVE-2026-57866 lets authenticated users abuse ai_generate_text() to exfiltrate secrets from configured Hadoop credential providers via SSRF.
A server-side request forgery affects Apache Impala versions 4.4.0 through 4.5.1. Authenticated users with permission to execute the ai_generate_text() function can exfiltrate secrets provided by credential providers configured via hadoop.security.credential.provider.path in core-site.xml. The attacker must know the secret's key name, and Apache rates the issue 'important'.
Next.js 16.4.0-canary.13 Image Optimizer DNS Rebinding TOCTOU SSRF Still Exists
Next.js 16.4.0-canary.13 Image Optimizer retains a DNS rebinding TOCTOU SSRF in fetchExternalImage() allowing requests to private network resources.
Next.js 16.4.0-canary.13 contains a DNS rebinding time-of-check-to-time-of-use Server-Side Request Forgery vulnerability in the Image Optimizer's fetchExternalImage() function. The code resolves the supplied hostname and checks the resulting addresses with isPrivateIp(), but a TOCTOU gap between resolution and the actual fetch allows an attacker-controlled DNS record to change and reach private network resources.
SonicWall's SMA1000 boxes under active attack again
SonicWall warns attackers are chaining two SMA1000 zero-days, a CVSS 10.0 SSRF and command injection, to compromise VPN gateways.
SonicWall says attackers are actively exploiting two chained zero-days in SMA 1000 appliances: CVE-2026-83548, a pre-authentication SSRF rated CVSS 10.0, and CVE-2026-83549, a post-authentication OS command injection (CVSS 7.8) in the Appliance Management Console. Hotfixes are available for SMA 6210, 7210, and 8200v appliances with no workarounds; SonicWall recommends reimaging compromised devices, rotating passwords, and resetting TOTP tokens. NHS England assesses further exploitation as almost certain, following a similar exploited pair in July when CISA added CVE-2026-15409 to its KEV catalog.
SonicWall Patches Two New Actively Exploited Zero
SonicWall patches two actively exploited SMA 1000 VPN zero-days: CVSS 10.0 pre-auth SSRF CVE-2026-83548 and post-auth command injection CVE-2026-83549, chained for RCE.
SonicWall released hotfixes for two zero-day vulnerabilities in its SMA 1000 VPN appliances, with SonicWall PSIRT confirming active exploitation in the wild. CVE-2026-83548 (CVSS 10.0) is a pre-authentication SSRF in the Appliance Work Place interface allowing unauthenticated unauthorized operations; CVE-2026-83549 (CVSS 7.8) is a post-authentication OS command injection in the Appliance Management Console enabling arbitrary command execution and RCE. The flaws affect models 6210, 7210 and 8200v running 12.4.3-03453 or earlier and 12.5.0-02835 or earlier, fixed in versions 12.4.3-03526 and 12.5.0-02952. This follows a July Volexity report on threat actor UTA0533 chaining two SMA 1000 zero-days to gain root access and deploy the KNUCKLEBALL Python backdoor.