05/13/2026
We've published our first security advisory. During a routine investigation into monitoring alerts, we discovered an unauthenticated SSRF vulnerability in the 66Uptime ping servers plugin that could expose cloud credentials, internal networks, and more.
The vulnerability has been patched by the developer, but upgrading alone isn't enough. API keys must be configured manually to be protected.
Full details, timeline, and remediation steps: https://www.glimmernet.com/security/gt-2026-001-ssrf-66uptime-ping-servers/
If you're running 66Uptime with remote ping servers, please read this.
Unauthenticated SSRF in the 66Uptime ping servers plugin enables cloud credential theft, internal network scanning, and arbitrary requests from affected servers