Back to blog

Follow and Subscribe

Matthew Mathur

Matthew Mathur

Senior Security Researcher, Fastly

Matthew is a Senior Security Researcher at Fastly, focusing on vulnerability research, web application attacks, and developing protections. Matthew is an active contributor to several open source security tools including the Metasploit Framework and Nuclei, and is passionate about sharing research with the security community.
What is Style Smuggler (CVE-2026-75650)?Matthew Mathur, Fastly Security Research Team
CVE-2026-75650 (StyleSmuggler) is a critical SSTI being actively exploited in ecommerce platforms. Learn what it is and how Fastly customers can stay protected.
Security
An illustration of a yellow, shining shield with a cracking gray shield peeling off of it
What is CVE-2026-66066? Protecting Your Rails App from Active Storage RCEMatthew Mathur, Fastly Security Research Team
Learn about CVE-2026-66066: An arbitrary file read vulnerability in Rails Active Storage. Understand the risks and protect your environment with our virtual patch.
Security
What is CVE-2026-23869? React Server Components Security AlertMatthew Mathur, Fastly Security Research Team
CVE-2026-23869: High-severity denial of service vulnerability in React Server Components. See impacts, affected versions, and get immediate protection with a virtual patch.
SecurityIndustry insights
AI Bots in Q2 2025: Trends from Fastly's Threat Insights ReportMatthew Mathur, David King, +1
Fastly's Q2 2025 Threat Insights Report uncovers how Meta, OpenAI, and others are shaping web traffic and what organizations need to do to stay in control.
SecurityIndustry insights+1
ToolShell Remote Code Execution in Microsoft SharePoint: CVE-2025-53770 & CVE-2025-53771Simran Khalsa, Matthew Mathur, +1
Microsoft revealed two critical vulnerabilities, CVE-2025-53771 and CVE-2025-53770, actively exploited to compromise SharePoint servers.
Security
TLS configuration icon
OS Command Injection ExplainedMatthew Mathur, Fastly Security Research Team
In this blog, we'll explore the web application vulnerability, OS Command Injection, and how to prevent it.
Security
CVE-2025-29927: Authorization Bypass in Next.jsMatthew Mathur, Fastly Security Research Team
A critical Next.js Vulnerability (CVE-2025-29927) lets attackers bypass authorization. Protect your applications now.
Security
Active exploitation of unauthenticated stored XSS vulnerabilities in WordPress PluginsFastly Security Research Team, Simran Khalsa, +2
We have observed active exploitation attempts targeting three high-severity CVEs: CVE-2024-2194, CVE-2023-6961, and CVE-2023-40000.
SecurityIndustry insights
CVE-2023-30534: Insecure Deserialization in Cacti prior to 1.2.25Fastly Security Research Team, Matthew Mathur
We have discovered two instances of insecure deserialization in Cacti versions prior to 1.2.25, tracked as CVE-2023-30534.
Security
Back to Basics: Directory TraversalFastly Security Research Team, Matthew Mathur
In this post, we'll explore the application vulnerability directory traversal. What is it and how can you protect your apps from it?
Security
Network Effect Threat Report: Uncovering the power of collective threat intelligenceFastly Security Research Team, Simran Khalsa, +3
Announcing the Network Effect Threat Report, Fastly’s threat intelligence report with insights based on unique data from April to June of 2023
SecurityIndustry insights+1
CVE-2023-34362: Progress MOVEit Transfer SQL Injection VulnerabilityFastly Security Research Team, Simran Khalsa, +3
What you need to know about CVE-2023-34362: Progress MOVEit Transfer SQL Injection Vulnerability
Security
Command Injection CVE-2021-25296: A Deep DiveFastly Security Research Team, Matthew Mathur
NagiosXI versions 5.5.6 to 5.7.5 are vulnerable to three different instances of command injection.
SecurityIndustry insights