A Server-Side Request Forgery (SSRF) vulnerability, identified as CVE-2020-37278, was reportedly exploited on the same day it was publicly disclosed. The vulnerability was reserved on October 2, 2026, and published on the same date.
The exploitation of CVE-2020-37278 was first listed in the VulnCheck KEV (Known Exploited Vulnerabilities) catalog on October 2, 2026. This listing was mirrored by the CIRCL aggregator on the same day. However, the vulnerability is not currently listed in the CISA KEV or the EUVD (European Union Vulnerability Database).
The claim of exploitation rests on a single commercial research catalog, VulnCheck KEV, which reported public exploitation evidence on October 2, 2026. No other independent catalog has corroborated this claim.
The vulnerability's CVSS severity score is currently listed as "none," and its EPSS (Exploit Prediction Scoring System) percentile is 27.1, with an EPSS score of 0.36%. The specific product or vendor affected by CVE-2020-37278 is not detailed in the available information, beyond its classification as an SSRF flaw.






