A server-side request forgery (SSRF) vulnerability, identified as CVE-2026-40242, in the getarcane arcane project has been added to VulnCheck's Known Exploited Vulnerabilities (KEV) catalog. The flaw was first disclosed on April 10, 2026, and evidence of its exploitation emerged approximately 160 days later, with its inclusion in the VulnCheck KEV on September 17, 2026.
The vulnerability's lifecycle began with its CVE reservation and publication on April 10, 2026. Public proof-of-concept (PoC) code was also published on the same day. Within a week, on April 17, 2026, initial reports of the vulnerability were observed on social media platforms, with further confirmation of its existence. A public report linking to a GitHub repository containing nuclei templates for the vulnerability was also noted on April 10, 2026.
While VulnCheck and CIRCL, an aggregator that mirrors VulnCheck's listings, have both cataloged CVE-2026-40242 as exploited, the claim of exploitation currently rests on these single sources. Neither the U.S. federal CISA KEV nor the European Union's ENISA EUVD have listed this vulnerability as exploited.
The vulnerability has an EPSS (Exploit Prediction Scoring System) score of 0.72%, placing it in the 52.3rd percentile, indicating a moderate likelihood of exploitation. The NVD record for CVE-2026-40242 provides further details on the vulnerability, though specific technical details of the SSRF flaw were not immediately available.






