Cross-Site Request Forgery (CSRF) is a malicious exploit where an attacker tricks an authenticated user into unknowingly submitting a request to a vulnerable web application. This can lead to unauthorized actions like transferring funds, changing passwords, or deleting accounts.