
CVE-2026-36758 A Server-Side Request Forgery (SSRF) in the /themes/-/install-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a craft… https://www.cve.org/CVERecord?id=CVE-2026-36758
Post summary
The entry announces a newly identified SSRF vulnerability in halo v2.22.14 that lets authenticated attackers scan internal resources, but it does not provide a PoC, exploit code, or patch information.


