CVE-2026-33626Active Exploitation(internlm / lmdeploy)

CRITICALCVSS 7.5 · HIGH

Exploitation observed; activity peaked at 29 mentions and remains active

Immediate actions

  • Patch internlm lmdeploy systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions prior to 0.12.3 have a Server-Side Request Forgery (SSRF) vulnerability in LMDeploy's vision-language module. The `load_image()` function in `lmdeploy/vl/utils.py` fetches arbitrary URLs without validating internal/private IP addresses, allowing attackers to access cloud metadata services, internal networks, and sensitive resources. Version 0.12.3 patches the issue.

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • lmdeploy

Threat summary

  • Active exploitation appears in 73 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 86 mentions across 20 observed days

What's happening

  • Active exploitation reported across 73 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 6 signals
  • Patch or workaround mentioned in 20 signals
  • Technical details provided in 49 signals
  • Disclosure: 5 classified signals
  • General: 5 classified signals
  • Peaked 16d ago at 29 mentions (2026-04-24); latest day: 2
  • 86 total mentions across 20 days

Affected systems

Vendors
Products
lmdeploy

Deep dive

Activity timeline86 mentions / 20d
07152229Mentions · 2026-04-21: 1Mentions · 2026-04-22: 2Mentions · 2026-04-23: 7Mentions · 2026-04-24: 29Mentions · 2026-04-25: 9Mentions · 2026-04-26: 5Mentions · 2026-04-27: 10Mentions · 2026-04-28: 2Mentions · 2026-04-29: 4Mentions · 2026-04-30: 4Mentions · 2026-05-02: 1Mentions · 2026-05-03: 1Mentions · 2026-05-06: 1Mentions · 2026-05-07: 1Mentions · 2026-05-09: 1Mentions · 2026-05-21: 1Mentions · 2026-05-24: 1Mentions · 2026-06-01: 3Mentions · 2026-06-11: 1Mentions · 2026-06-21: 2PoC Mentioned / Linked · 2026-04-24: 3PoC Mentioned / Linked · 2026-04-27: 1PoC Mentioned / Linked · 2026-05-07: 1PoC Mentioned / Linked · 2026-05-09: 1Exploit Tool / Code · 2026-04-23: 1Active Exploitation · 2026-04-22: 2Active Exploitation · 2026-04-23: 7Active Exploitation · 2026-04-24: 27Active Exploitation · 2026-04-25: 7Active Exploitation · 2026-04-26: 4Active Exploitation · 2026-04-27: 7Active Exploitation · 2026-04-28: 2Active Exploitation · 2026-04-29: 3Active Exploitation · 2026-04-30: 3Active Exploitation · 2026-05-02: 1Active Exploitation · 2026-05-03: 1Active Exploitation · 2026-05-06: 1Active Exploitation · 2026-05-07: 1Active Exploitation · 2026-05-09: 1Active Exploitation · 2026-05-21: 1Active Exploitation · 2026-05-24: 1Active Exploitation · 2026-06-01: 3Active Exploitation · 2026-06-11: 1Patch / Workaround · 2026-04-23: 1Patch / Workaround · 2026-04-24: 9Patch / Workaround · 2026-04-25: 2Patch / Workaround · 2026-04-27: 2Patch / Workaround · 2026-04-29: 1Patch / Workaround · 2026-04-30: 1Patch / Workaround · 2026-05-06: 1Patch / Workaround · 2026-05-07: 1Patch / Workaround · 2026-05-09: 1Patch / Workaround · 2026-06-11: 1Technical Details · 2026-04-21: 1Technical Details · 2026-04-23: 4Technical Details · 2026-04-24: 15Technical Details · 2026-04-25: 2Technical Details · 2026-04-27: 6Technical Details · 2026-04-28: 2Technical Details · 2026-04-29: 4Technical Details · 2026-04-30: 4Technical Details · 2026-05-03: 1Technical Details · 2026-05-06: 1Technical Details · 2026-05-07: 1Technical Details · 2026-05-09: 1Technical Details · 2026-05-21: 1Technical Details · 2026-06-01: 3Technical Details · 2026-06-11: 1Technical Details · 2026-06-21: 204-2104-2304-2504-2704-2905-0205-0605-0905-2406-1106-21
Signal classification5 categories
Active Exploitation
7283.7%
Disclosure
55.8%
General
55.8%
Patch
33.5%
PoC
11.2%
Referenced assets42 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-211
Disclosure1
2026-04-222
Active Exploitation2
2026-04-237
Active Exploitation6Patch1
2026-04-2429
Active Exploitation27General2
2026-04-259
Active Exploitation7General1Patch1
2026-04-265
Active Exploitation4General1
2026-04-2710
Active Exploitation7General1Patch1PoC1
2026-04-282
Active Exploitation2
2026-04-294
Active Exploitation3Disclosure1
2026-04-304
Active Exploitation3Disclosure1
2026-05-021
Active Exploitation1
2026-05-031
Active Exploitation1
2026-05-061
Active Exploitation1
2026-05-071
Active Exploitation1
2026-05-091
Active Exploitation1
2026-05-211
Active Exploitation1
2026-05-241
Active Exploitation1
2026-06-013
Active Exploitation3
2026-06-111
Active Exploitation1
2026-06-212
Disclosure2
Full discourse20 posts
  • Nicolas Krassas@Dinosn
    Active Exploitation

    LMDeploy CVE-2026-33626 Flaw Exploited Within 13 Hours of Disclosure https://thehackernews.com/2026/04/lmdeploy-cve-2026-33626-flaw-exploited.html

    Post summary

    The LMDeploy CVE-2026-33626 flaw was actively exploited within 13 hours of its disclosure, but no PoC, patch, or technical details are provided in the text.

    1801902.2K
    158.1K followersView on X
  • 𝓝𝓲𝓭𝓸𝓾𝓲𝓵𝓵𝓮 🐙🐙@_Nidouille_
    Active Exploitation

    Une faille critique (CVE-2026-33626, CVSS 7.5) dans LMDeploy, un outil open-source pour le déploiement de LLMs, est activement exploitée dans la nature moins de 13h après sa divulgation ! https://thehackernews.com/2026/04/lmdeploy-cve-2026-33626-flaw-exploited.html

    Post summary

    The article reports that CVE-2026-33626 is critically flawed and has been actively exploited within 13 hours of disclosure, yet it offers no PoC, exploit code, or patch information.

    1701122.6K
    10.4K followersView on X
  • Blue Team News@blueteamsec1
    Active Exploitation

    LMDeploy CVE-2026-33626 Flaw Exploited Within 13 Hours of Disclosure http://dlvr.it/TShvhs #CyberSecurity #Vulnerability #CVE2026 #SSRF #DataProtection https://t.co/tk3kcH2D7y

    Post summary

    The LMDeploy flaw (CVE‑2026‑33626) was actively exploited within 13 hours of disclosure, underscoring an urgent threat with no patch or PoC details provided.

    0101341.5K
    56.6K followersView on X
  • Sysdig@sysdig
    Active Exploitation

    🚨 From disclosure to exploitation in just 12 hours.  A newly disclosed SSRF vulnerability in LMDeploy (CVE-2026-33626) was exploited shortly after the GitHub advisory was published, with no public PoC available. ↳ Read the full breakdown https://okt.to/xjAYPC https://t.co/oEVlBq0ff1

    Post summary

    The post reports that CVE-2026-33626, an SSRF flaw in LMDeploy, was actively exploited within 12 hours of disclosure, with no publicly available PoC or patch information.

    030100442
    10.3K followersView on X
  • AI Security Gateway@AISGateway
    Active Exploitation

    🚨CVE-2026-33626 dropped Friday. By Saturday morning it was already being exploited in the wild. 13 hours from disclosure to active attack on an LLM deployment toolkit. That's not a slow burn — that's a fire before you've even read the alert. #LLMSecurity #AISecurity

    Post summary

    CVE-2026-33626 was disclosed Friday and reportedly exploited in the wild by Saturday morning, highlighting rapid real‑world attacks on an LLM deployment toolkit.

    1303081
    44 followersView on X
  • Inspectiv@inspectiv
    Active Exploitation

    LMDeploy CVE-2026-33626 Flaw Exploited Within 13 Hours of Disclosure SSRF vulnerability in LMDeploy (open-source LLM deployment toolkit) was exploited just 12.5 hours after public disclosure on GitHub. Attackers can steal cloud credentials, access internal services, an... #CyberSecurity #AppSec

    Post summary

    The text reports that the SSRF vulnerability in LMDeploy (CVE-2026-33626) was actively exploited within 12.5 hours of its public disclosure, enabling attackers to steal cloud credentials and access internal services.

    00042397
    2.7K followersView on X
  • The Cyber Security Hub™@TheCyberSecHub
    Active Exploitation

    LMDeploy CVE-2026-33626 Flaw Exploited Within 13 Hours of Disclosure https://thehackernews.com/2026/04/lmdeploy-cve-2026-33626-flaw-exploited.html?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The article reports that the CVE-2026-33626 flaw in LMDeploy was actively exploited within 13 hours of its disclosure.

    11021582
    194.5K followersView on X
  • Andre Gironda@AndreGironda
    Active Exploitation

    CVE-2026-33626 how attackers exploited LMDeploy LLM inference engines in 12 hours -- https://webflow.sysdig.com/blog/cve-2026-33626-how-attackers-exploited-lmdeploy-llm-inference-engines-in-12-hours

    Post summary

    The text confirms that attackers actively exploited CVE-2026-33626 on LMDeploy LLM inference engines within a 12‑hour period, illustrating real‑world use of the vulnerability.

    01040362
    3.8K followersView on X
  • AWS Security Digest@AwsSecDigest
    Active Exploitation

    How attackers exploited LMDeploy LLM inference engines in 12 hours Sysdig LMDeploy’s chat-completion "yolo" endpoint blindly fetches whatever URL is in image_url, turning the model server into an SSRF proxy. Within 13 hours of the CVE, attackers hit a Sysdig honeypot and — in ~8 minutes — pulled AWS IAM credentials from the metadata service, port-scanned Redis and MySQL, then reached an unauthenticated admin endpoint. 🔍 Technical takeaways - Exploit vector: unchecked image_url → SSRF via "yolo". - Impact chain: SSRF → metadata access → IAM token theft → lateral scanning (Redis/MySQL) → unauthenticated admin access. - Timeline: CVE public → 13 hours to first compromise; 8 minutes from access to credential exfiltration. 🛡️ How to reduce risk - Sanitize or block arbitrary remote fetches; validate URLs. - Restrict inference-server egress and use network allowlists. - Harden instance metadata access (IMDS protections) and enforce least-privilege IAM. - Require auth on admin endpoints and monitor outbound requests for SSRF signs. Source: AWS Security Digest Issue #258 — https://awssecuritydigest.com/past-issues/aws-security-digest-258 Read here: https://webflow.sysdig.com/blog/cve-2026-33626-how-attackers-exploited-lmdeploy-llm-inference-engines-in-12-hours

    Post summary

    The article reports that attackers exploited an LLN deployment via SSRF to steal AWS IAM credentials within 13 hours of CVE disclosure, detailing the exploitation chain and remediation steps.

    00022194
    1.7K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨High - LMDeploy SSRF (CVE-2026-33626) A Server - Side Request Forgery flaw in the vision - language module allows attackers to fetch arbitrary URLs via load_image() - exposing cloud metadata services & internal networks with no IP validation. 👉 Upgrade to 0.12.3 immediately

    Post summary

    LMDeploy has a high‑severity SSRF (CVE‑2026‑33626) that allows attackers to request arbitrary URLs and access internal metadata services; a patch is available—upgrade to version 0.12.3 immediately.

    00040107
    237 followersView on X
  • Dr.Philippe Vynckier, CISSP - Influencer@PVynckier
    Active Exploitation

    LMDeploy CVE-2026-33626 Flaw Exploited Within 13 Hours of Disclosure https://thehackernews.com/2026/04/lmdeploy-cve-2026-33626-flaw-exploited.html

    Post summary

    LMDeploy CVE-2026-33626 was exploited within 13 hours of its disclosure, showing active exploitation in the wild, but no PoC, exploit tool, patch, or technical details are provided in the headline.

    03010169
    24.1K followersView on X
  • QuanChain@Quan_Chain
    Active Exploitation

    A critical vulnerability exploited in 13 hours tells you more about modern security timelines than any threat report. CVE-2026-33626 was patched, disclosed, and actively weaponised before most teams had even read the advisory. The gap between "vulnerability exists" and "vulnerability is being used against you" is now measured in hours, not weeks. Static security models assume defenders have time to respond. Increasingly, they don't. QuanChain's LQCp/h Oracle monitors threat conditions in real-time across 7 escalation levels, triggering automatic migration to stronger key hierarchies before a response window even opens. How long does your current infrastructure's manual upgrade cycle actually take?

    Post summary

    The post highlights rapid weaponisation and patching of CVE‑2026‑33626, underscoring an unusually short exploitation window, but provides no technical or PoC details.

    20020129
    92.8K followersView on X
  • Vivek | Cybersecurity@VivekIntel
    Active Exploitation

    🚨 LMDeploy SSRF flaw exploited within hours (CVE-2026-33626) SSRF in image loader → attackers access internal services + steal cloud data 💡 Lesson: Patch delay = compromise — attackers weaponize vulnerabilities almost instantly ⚠️ Action: Update immediately + block internal metadata access (IMDS) + monitor outbound SSRF patterns https://thehackernews.com/2026/04/lmdeploy-cve-2026-33626-flaw-exploited.html

    Post summary

    CVE-2026-33626 is an SSRF vulnerability in LMDeploy that was exploited within hours, allowing attackers to access internal services and steal cloud data; the post urges immediate patching and blocking of internal metadata access.

    11020276
    16.1K followersView on X
  • RST Cloud@rst_cloud
    Active Exploitation

    #threatreport #LowCompleteness CVE-2026-33626: How attackers exploited LMDeploy LLM Inference Engines in 12 hours | 22-04-2026 Source: https://webflow.sysdig.com/blog/cve-2026-33626-how-attackers-exploited-lmdeploy-llm-inference-engines-in-12-hours Key details below ↓ 🎯Victims: Lmdeploy, Artificial intelligence infrastructure, Inference servers, Model gateways, Agent orchestration tools 🔓CVEs: CVE-2026-33626 \[[Vulners](https://vulners.com/cve/CVE-2026-33626)] - CVSS V3.1: *7.5*, - Vulners: Exploitation: True Soft: - internlm lmdeploy (<0.12.3) 📚TTPs: ⚔️Tactics: 1 🛠️Technics: 0 🤖LLM extracted TTPs:` T1016.001, T1046, T1190, T1499.004, T1552.005 🧨IOCs: - IP: 3 - Domain: 1 - File: 1 - Url: 1 💽Software: Redis, MySQL, OpenAI, Ollama, Docker 🔠Functions: _is_safe_url #threatreport: On April 21, 2026, a Server-Side Request Forgery (SSRF) vulnerability, registered as CVE-2026-33626, was identified in LMDeploy, a toolkit designed for serving vision-language and text large language models created by Shanghai AI Laboratory. The vulnerability stems from a lack of hostname resolution checks, the absence of a private-network blocklist, and insufficient protection for link-local addresses. Consequently, any URL with an http:// or https:// scheme could be fetched and relayed by the server, enabling potential attackers to exploit this weakness. Just over 12 hours after the vulnerability was disclosed, attempts to exploit it were observed. The Sysdig Threat Research Team noted that the attacker utilized the vision-language image loader to conduct port scans on the internal network. This revealed significant targets, including the AWS Instance Metadata Service (IMDS), Redis, MySQL databases, additional HTTP administrative interfaces, and out-of-band DNS exfiltration points. The exploitation was characterized by a rapid, eight-minute session where the first request directly targeted the AWS IMDS followed by probing the Redis loopback port. The attacker's strategy showcased how the SSRF could be weaponized within a cloud infrastructure context, taking advantage of common ports such as 6379 for Redis, known for being targeted following IMDS access. Following this reconnaissance, further attempts were made to establish egress points using an out-of-band DNS callback to exfiltrate data. The implications of CVE-2026-33626 are profound, particularly as it highlights a troubling trend: critical vulnerabilities in AI-related infrastructure are increasingly being exploited within hours post-disclosure. Attackers can leverage these vulnerabilities to gain access to sensitive resources, including IAM credentials and cloud metadata. Such access can lead to severe ramifications, including compromising cloud accounts and disrupting service via denials of service on inference processes. Defensive strategies are vital considering this pattern of rapid exploitation. Application layer protections should include logging and alerting for requests made to internal network ranges or well-known service ports. Moreover, at the host layer, runtime detection should focus on identifying outbound connections from inference processes, particularly to cloud metadata endpoints. The swift identification of exploitation attempts underscores the need for proactive security measures, distancing from reliance on delayed patches or scans to ensure the integrity of AI-serving frameworks in the face of emerging threats.

    Post summary

    Within 12 hours of discovery, attackers leveraged the SSRF flaw in LMDeploy to access cloud metadata and internal services; no PoC, patch, or workaround is provided.

    10020115
    695 followersView on X
  • ninp0@ninp0
    PoC

    New on 0dayinc: CVE-2026-33626 and the LMDeploy Vision-Language SSRF Exposure — SSRF root cause, weaponization window, public PoC references, and safe lab-only validation steps for defenders. https://www.0dayinc.com/post/whitepaper-cve-2026-33626-and-the-lmdeploy-vision-language-ssrf-exposure

    Post summary

    The post announces CVE-2026-33626, details its SSRF root cause and weaponization window, and references public PoC materials, but does not provide exploit code or evidence of active exploitation.

    01011162
    494 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2024-32002 2 - CVE-2025-20333 3 - CVE-2026-20131 4 - CVE-2026-33626 5 - CVE-2024-57726 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The note simply enumerates current trending CVE identifiers without offering any detailed or actionable information.

    00021725
    1.7K followersView on X
  • Gray Hats@the_yellow_fall
    Active Exploitation

    CVE-2026-33626: A critical SSRF in LMDeploy exploited in under 13 hours. Learn how attackers hijack AI nodes and how to secure your inference cloud now. #CVE202633626 #SSRF #AISecurity #LMDeploy #InfoSec #CyberAttack #CloudSecurity #LLM #PatchNow https://securityonline.info/cve-2026-33626-lmdeploy-ssrf-ai-inference-hijack/ https://t.co/09IZxf21rQ

    Post summary

    The message highlights that CVE-2026-33626, a critical SSRF in LMDeploy, is actively being exploited in the wild, with no PoC or patch details provided.

    00021429
    12.5K followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    Active Exploitation

    🚨 #AI INFRA UNDER FIRE: #CVE-2026-33626 SSRF Exploited in the Wild Within 13 Hours—Is Your LLM Inference Engine the Next Target? + Video https://undercodetesting.com/ai-infra-under-fire-cve-2026-33626-ssrf-exploited-in-the-wild-within-13-hours-is-your-llm-inference-engine-the-next-target-video/ Educational Purposes!

    Post summary

    A linked video claims that CVE‑2026‑33626, an SSRF flaw in AI infrastructure, was exploited in the wild within 13 hours after disclosure, showing evidence of real‑world attacks but providing no patch or PoC details.

    1001050
    520 followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-33626 - high 🚨 LMDeploy - Server-Side Request Forgery &gt; LMDeploy is a toolkit for compressing, deploying, and serving large language models. ... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-33626 @pdnuclei #NucleiTemplates #cve

    Post summary

    A high‑severity SSRF vulnerability (CVE‑2026‑33626) has been disclosed in the LMDeploy toolkit. Details and detection templates are available via the Project Discovery library link.

    00011160
    942 followersView on X
  • motch | セキュリティ🛡️@motch_dev
    Active Exploitation

    🚨緊急速報🚨 LMDeployに深刻な脆弱性(CVE-2026-33626)!公開からわずか13時間で悪用開始 SSRFにより内部情報漏洩の危険!バージョン0.12.0以前は至急アップデートを! あなたのシステムは大丈夫?今すぐ確認を! #セキュリティ #LMDeploy https://t.co/kDqK63eqLd

    Post summary

    A newly disclosed CVE-2026-33626 in LMDeploy is actively exploited via SSRF within 13 hours of disclosure, posing an internal information leak risk; immediate patching to version 0.12.0 or newer is required.

    1000180
    267 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appinternlmlmdeploy---

Explore more