feeds.feedburner.com • 2026-04-24 07:24

LMDeploy CVE-2026-33626 Flaw Exploited Within 13 Hours of Disclosure

thumb
A high-severity security flaw in LMDeploy, an open-source toolkit for compressing, deploying, and serving large language models (LLMs), has come under active exploitation in the wild less than 13 hours after its public disclosure. The vulnerability, tracked as CVE-2026-33626 (CVSS score: 7.5), relates to a Server-Side Request Forgery (SSRF) vulnerability that could be exploited to access
Read original