Risk intelligence agency GreyNoise is warning of a “coordinated surge” within the exploitation of Server-Facet Request Forgery (SSRF) vulnerabilities spanning a number of platforms.
“At the very least 400 IPs have been seen actively exploiting a number of SSRF CVEs concurrently, with notable overlap between assault makes an attempt,” the corporate stated, including it noticed the exercise on March 9, 2025.
The international locations which have emerged because the goal of SSRF exploitation makes an attempt embody america, Germany, Singapore, India, Lithuania, and Japan. One other notable nation is Israel, which has witnessed a surge on March 11, 2025.

The listing of SSRF vulnerabilities being exploited are listed under –

GreyNoise stated that most of the identical IP addresses are focusing on a number of SSRF flaws directly quite than specializing in one explicit weak spot, noting the sample of exercise suggests structured exploitation, automation, or pre-compromise intelligence gathering.
In gentle of lively exploitation makes an attempt, it is important that customers apply the newest patches, restrict outbound connections to obligatory endpoints, and monitor for suspicious outbound requests.
“Many fashionable cloud companies depend on inside metadata APIs, which SSRF can entry if exploited,” GreyNoise stated. “SSRF can be utilized to map inside networks, find weak companies, and steal cloud credentials.”