Tag

Ssrf

All articles tagged with #ssrf

Massive data theft follows zero-day flaw in Oracle PeopleSoft
technology2 months ago

Massive data theft follows zero-day flaw in Oracle PeopleSoft

A critical PeopleSoft zero-day (CVE-2026-35273) was exploited by the ShinyHunters ransomware group to target about 100 organizations, stealing gigabytes of data and pressuring victims for ransom. The flaw is a remotely exploitable SSRF vulnerability, and Oracle has issued mitigations but not a full patch yet. Roughly 68% of affected entities are in higher education, including the University of Nottingham, with attackers mapping configurations and exfiltrating data to a data-leak site, where some victims’ data was published; Mandiant and Rapid7 are providing IOCs and remediation guidance.

Cisco patches critical Unified CM flaw that could grant root access via SSRF
security2 months ago

Cisco patches critical Unified CM flaw that could grant root access via SSRF

Cisco released security updates for a critical flaw in Unified CM (CVE-2026-20230) that can be exploited remotely through SSRF to write files and escalate to root. A public PoC exists, but there is no evidence of active exploitation yet. The vulnerability affects systems with WebDialer enabled (WebDialer is disabled by default); admins are urged to upgrade to 14SU6 or 15SU5 or disable WebDialer as a temporary measure until patches are applied.

Microsoft Azure API Management Service Vulnerabilities Patched
api-management-vulnerability3 years ago

Microsoft Azure API Management Service Vulnerabilities Patched

Three new security flaws have been discovered in Microsoft Azure API Management service, including two server-side request forgery (SSRF) flaws and one instance of unrestricted file upload functionality in the API Management developer portal. Exploitation of SSRF flaws can result in loss of confidentiality and integrity, permitting a threat actor to read internal Azure resources and execute unauthorized code. Following responsible disclosure, all the three flaws have been patched by Microsoft.