
CVE-2026-72581 - SSRF in duhow/xiaoai-patch lets attackers hit internal networks via Xiaomi smart speaker. CVSS 8.6. Unpatched. Block access or update once fixed. #CVE #infosec #IoT https://www.valtersit.com/cve/CVE-2026-72581/ #infosec #cybersecurity #CVE #Linux #infosec #infosec #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu #debian
Post summary
The tweet highlights an unpatched SSRF vulnerability (CVE‑2026‑72581) in a Xiaomi smart speaker, provides technical details, and urges users to block traffic or wait for a vendor fix.
