Threat actors actively weaponize high-severity flaw CVE-2026-33626 in LMDeploy within hours of release, using multimodal image loaders as SSRF proxies into cloud metadata.
Google Cloud resolves high-severity SSRF vulnerability CVE-2026-19486 in Gemini Enterprise Agent Platform App Builder allowing attackers to harvest GCP IAM service account tokens.