VulnWatch VulnWatch
← Back to dashboard
Unknown rss_thehackernews · rss_a7af71ea4aa1d6d4c118462376eee3a0

LMDeploy CVE-2026-33626 Flaw Exploited Within 13 Hours of Disclosure

Published Apr 24, 2026

A high-severity security flaw in LMDeploy, an open-source toolkit for compressing, deploying, and serving large language models (LLMs), has come under active exploitation in the wild less than 13 hours after its public disclosure. The vulnerability, tracked as CVE-2026-33626 (CVSS score: 7.5), relates to a Server-Side Request Forgery (SSRF) vulnerability that could be exploited to access

Affected AI Products

large language model llm
Get the weekly digest. Every Monday: top AI security stories of the week. Free.