Criminal IP[verified]@CriminalIP_USActive Exploitation
CVE‑2021‑39935 is a GitLab CI Lint API SSRF vulnerability that has been actively exploited, confirmed by its inclusion in the CISA KEV. The flaw permits unauthenticated attackers to make internal server requests, and unpatched instances remain exposed.
piyokango[verified]@piyokangoActive Exploitation
CISA has confirmed that four CVEs are actively exploited and added them to the KEV catalog, providing high CVSS scores and vendor advisory links that include patch information.
Clandestine[verified]@akaclandestineDisclosure
A new vulnerability (CVE‑2021‑39935) affecting GitLab CI Lint API via Server‑Side Request Forgery has been disclosed, with a reference link to Criminal IP for additional context.
Machina Record[verified]@MachinaRecordActive Exploitation
The text reports that multiple CVEs—including those in VMware ESXi, React2Shell, Google Looker, GitLab, n8n, and WinRAR—are being actively exploited, with some exploits publicly disclosed but no patches or mitigations mentioned.
Criminal IP Japan[verified]@CriminalIP_JPActive Exploitation
The post reports confirmed active exploitation of CVE-2021-39935 on exposed GitLab instances, highlighting the SSRF risk and urging patch verification and environment scans.
キタきつね[verified]@foxbookDisclosure
The announcement notes that CISA has added four previously known exploited vulnerabilities to its catalog, listing their brief technical details without providing PoC, exploit code, patches, or mitigation information.
Criminal IP Korea[verified]@CriminalIP_KRActive Exploitation
The GitLab SSRF flaw (CVE‑2021‑39935) has resurfaced with active exploitation confirmed; patching and access controls are recommended.
Rory J Bernier[verified]@RoryCraveActive Exploitation
CISA has listed four CVEs as actively exploited in the wild, including SolarWinds Web Help Desk RCE and GitLab SSRF, and urges immediate patching.