# AI exploitation timeline

Published articles for AI exploitation timeline.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## CVE-2026-33626: How attackers exploited LMDeploy LLM Inference Engines in 12 hours

DevFeed: [CVE-2026-33626: How attackers exploited LMDeploy LLM Inference Engines in 12 hours](<https://devfeed.tech/articles/cve-2026-33626-how-attackers-exploited-lmdeploy-llm-inference-engines-in-12-hours-53208.md>)

Original publisher: [Read original article](<https://webflow.sysdig.com/blog/cve-2026-33626-how-attackers-exploited-lmdeploy-llm-inference-engines-in-12-hours>)

Author: Sysdig Threat Research Team

Published: 2026-04-22T00:00:00Z

Content type: article

Language: en

Sources: [Sysdig Blog](<https://devfeed.tech/sources/sysdig-blog.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>), [AI Infrastructure](<https://devfeed.tech/topics/ai-infrastructure.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [Inference](<https://devfeed.tech/topics/inference.md>), [API](<https://devfeed.tech/topics/api.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [MySQL](<https://devfeed.tech/topics/mysql.md>), [Redis](<https://devfeed.tech/topics/redis.md>)

Tags: [ai-exploitation-timeline](<https://devfeed.tech/tags/ai-exploitation-timeline.md>), [ai-infrastructure-security](<https://devfeed.tech/tags/ai-infrastructure-security.md>), [ai-model-serving-security](<https://devfeed.tech/tags/ai-model-serving-security.md>), [aws](<https://devfeed.tech/tags/aws.md>), [cloud-metadata-attack](<https://devfeed.tech/tags/cloud-metadata-attack.md>), [cloud-security-threats](<https://devfeed.tech/tags/cloud-security-threats.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-33626](<https://devfeed.tech/tags/cve-2026-33626.md>), [enumeration](<https://devfeed.tech/tags/enumeration.md>), [exploited](<https://devfeed.tech/tags/exploited.md>), [falco-rules](<https://devfeed.tech/tags/falco-rules.md>), [genai-security-risks](<https://devfeed.tech/tags/genai-security-risks.md>), [imds-exploitation](<https://devfeed.tech/tags/imds-exploitation.md>), [inference-server-vulnerabilities](<https://devfeed.tech/tags/inference-server-vulnerabilities.md>), [internal-network-scanning](<https://devfeed.tech/tags/internal-network-scanning.md>), [llm](<https://devfeed.tech/tags/llm.md>), [llm-inference](<https://devfeed.tech/tags/llm-inference.md>), [llm-security](<https://devfeed.tech/tags/llm-security.md>), [llmdeploy-exploit](<https://devfeed.tech/tags/llmdeploy-exploit.md>), [lmdeploy-vulnerability](<https://devfeed.tech/tags/lmdeploy-vulnerability.md>), [mysql](<https://devfeed.tech/tags/mysql.md>), [redis](<https://devfeed.tech/tags/redis.md>), [runtime-security](<https://devfeed.tech/tags/runtime-security.md>), [server-side-request-forgery](<https://devfeed.tech/tags/server-side-request-forgery.md>), [ssrf-attack](<https://devfeed.tech/tags/ssrf-attack.md>), [ssrf-detection](<https://devfeed.tech/tags/ssrf-detection.md>), [sysdig-threat-research](<https://devfeed.tech/tags/sysdig-threat-research.md>), [vision-llm-exploit](<https://devfeed.tech/tags/vision-llm-exploit.md>)

### AI overview

A Sysdig Threat Research Team report describes CVE-2026-33626, an SSRF vulnerability in LMDeploy, and says attackers exploited it within 12 hours of disclosure. The attackers used the vision-language image loader to scan internal services, access cloud metadata, and perform DNS exfiltration.

### Source excerpt

CVE-2026-33626 in LMDeploy was exploited within 12 hours of disclosure, enabling attackers to use a vision-LLM endpoint for SSRF-based internal network scanning, cloud metadata access, and service enumeration.