A server-side request forgery (SSRF) vulnerability, identified as CVE-2022-45362, in the Paytm Payment Gateway has been added to VulnCheck's Known Exploited Vulnerabilities (KEV) catalog. This addition indicates that the flaw is actively being exploited in the wild.
The vulnerability was first disclosed on December 7, 2023, and was reserved as a CVE on November 14, 2022. According to VulnCheck's data, the first confirmed exploitation of CVE-2022-45362 occurred approximately 1015 days after its initial disclosure, with its first KEV listing on September 17, 2026. Public reports of exploitation activity date back to December 8, 2023, and December 30, 2023.
While VulnCheck and CIRCL, an aggregator that mirrors VulnCheck's listings, have included CVE-2022-45362 in their exploited vulnerability lists, it has not yet been added to the CISA KEV catalog maintained by the U.S. federal government or the EUVD by ENISA, the European Union's cybersecurity agency. The current assessment of the vulnerability's severity is not specified, and its Exploit Prediction Scoring System (EPSS) score is 41.8%, placing it in the 98.6th percentile.
The inclusion in VulnCheck's KEV catalog serves as a critical alert for organizations utilizing the Paytm Payment Gateway, urging them to prioritize patching and mitigation efforts. The presence of public exploitation evidence underscores the immediate threat posed by this SSRF flaw.






