FR
live
weakness type

CWE-502

The application rebuilds an object from attacker-controlled data, which often leads to code execution.

218
vulnerabilities tracked
5
under active exploitation
83
critical
26 August 2026
latest publication
Most affected vendors
cve

Vulnerability watch

idvulnerabilityseveritypublished
CVE-2021-23758Ajax.NET Professional Deserialization of Untrusted Data VulnerabilityAjax.NET Professional Critical 26/08 CVE-2026-15679Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face PyTorch Image Models. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of checkpoints. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-27987.NVD analysis in progress High CVSS 7.8 20/08 CVE-2026-18285Aeon load_rehab_pile_dataset Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Aeon. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the load_rehab_pile_dataset method. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28749.NVD analysis in progress High CVSS 7.8 20/08 CVE-2026-66583Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions. Critical CVSS 9.8 20/08 CVE-2026-66672Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions. Critical CVSS 9.8 20/08 CVE-2026-69836Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.Microsoft Entra Id Critical CVSS 10 20/08 CVE-2026-73993Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions. Critical CVSS 9.8 20/08 CVE-2026-77645A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.NVD analysis in progress Critical CVSS 9.2 20/08 CVE-2026-77646A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.NVD analysis in progress High CVSS 7.7 20/08 CVE-2026-44901Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, AffectedItemsWazuhResult.merge() in framework/wazuh/core/results.py trusts the sort_casting field in a cluster worker's JSON response. During a distributed API merge, attacker-controlled type names are resolved through Python builtins without an allowlist. A compromised worker can set sort_casting to exec and place Python source in affected_items, causing the master to execute the payload as root when responses from multiple nodes are merged. This issue is fixed in versions 4.14.6 and 5.0.0-beta2.NVD analysis in progress High CVSS 8.4 19/08 CVE-2026-49816Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.Dell Command Update High CVSS 7.8 19/08 CVE-2026-49817Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.Dell Command Update High CVSS 7.8 19/08 CVE-2026-73364Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions. Critical CVSS 9.8 19/08 CVE-2026-73389Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions. Critical CVSS 9.8 19/08 CVE-2026-75987A vulnerability was found in SPLWare esProc up to 20260507. This affects the function ObjectInputStream.readUnshared of the file src/main/java/com/scudata/parallel/SocketData.java. Performing a manipulation results in deserialization. Remote exploitation of the attack is possible. High CVSS 7.3 19/08 CVE-2026-76395In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the Splunk server by loading a model file containing crafted sparse matrix data. The deserialization of untrusted data is possible because a model codec in Splunk AI Toolkit deserializes sparse matrix data without guarding against embedded pickle content. For more information see Troubleshoot the Splunk Machine Learning Toolkit (https://help.splunk.com/en/splunk-cloud-platform/apply-machine-learning/machine-learning-toolkit-user-guide/5.5.0/troubleshooting-mltk/troubleshoot-the-splunk-machine-learning-toolkit) in the Splunk documentation.Splunk Ai Toolkit High CVSS 8.8 19/08 CVE-2026-76404In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands on the underlying operating system. The vulnerability is possible because of missing input validation in the app's credential management component, which deserializes stored data without checking whether the content is of the expected type.Splunk Model Context Protocol Server Critical CVSS 9.1 19/08 CVE-2026-76850LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine in lmdeploy/pytorch/disagg/conn/engine_conn.py reads peer-to-peer cache-free requests with recv_pyobj(), which deserializes the received bytes with pickle.loads(), and the isinstance check against DistServeCacheFreeRequest runs only after deserialization has already completed. The peer that supplies those bytes is caller-controlled: p2p_connect passes remote_engine_endpoint_info.zmq_address from the request body to connect() on the ZMQ PULL socket, and the POST /distserve/p2p_initialize and /distserve/p2p_connect endpoints in lmdeploy/serve/openai/api_server.py apply no authentication unless the server is started with api_keys, which defaults to None. A remote attacker can direct an engine to pull from a ZMQ endpoint under their control and execute arbitrary code in the engine process. Deployments that do not enable disaggregated serving are not affected, because the receive loop is only started once the migration backend accepts the connection.NVD analysis in progress Critical CVSS 9.8 19/08 CVE-2026-32465Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions. High CVSS 8.8 18/08 CVE-2026-32470Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions. Critical CVSS 9.8 18/08 CVE-2026-59940Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values from the general deserialization reference table without verifying genuine internal Promise resolver records, causing deserialization side effects with plugins enabled and potentially unintended server-side invocation or remote code execution when downstream frameworks register callable wrappers. This issue is fixed in version 1.5.3.NVD analysis in progress Critical CVSS 9.8 18/08 CVE-2026-60392Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In PDF Export SDK). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).Oracle Outside In Technology High CVSS 7.8 18/08 CVE-2026-60412Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).Oracle Outside In Technology High CVSS 7.8 18/08 CVE-2026-66620Editor PHP Object Injection in OptionTree <= 2.7.3 versions. High CVSS 7.2 18/08 CVE-2026-73341Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions. Critical CVSS 9.8 18/08 CVE-2026-73366Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions. Critical CVSS 9.8 18/08 CVE-2026-73376Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions. Critical CVSS 9.8 18/08 CVE-2026-73380Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions. Critical CVSS 9.8 18/08 CVE-2026-73397Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions. Critical CVSS 9.8 18/08 CVE-2026-74012Deserialization of Untrusted Data vulnerability in TaxoPress allows Object Injection. This issue affects TaxoPress: from n/a through 3.51.0. High CVSS 8.8 18/08 CVE-2026-16138In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted file metadata can allow a user with write access to a Network share to execute arbitrary code on the Storage Zones Controller host.NVD analysis in progress High CVSS 8 17/08 CVE-2024-13784The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8.5 via deserialization of untrusted input from form submissions. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present. Critical CVSS 9.8 16/08 CVE-2026-16099The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_link_item function in all versions up to, and including, 4.5.3. This makes it possible for authenticated attackers, with contributor-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). A viable POP chain exists within the plugin itself via Podlove\ImageCache\GenerationGuard, whose __destruct() method invokes wp_delete_file() with an attacker-controlled file path populated through unserialization. High CVSS 8.8 16/08 CVE-2025-7639The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Operator" privilege to tamper with serialized data, potentially resulting in code execution during deserialization under the privilege of Enterprise SCADA security group "DNA Apps".NVD analysis in progress High CVSS 7.1 14/08 CVE-2026-19826A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function Hessian2Input.readObject of the file /serialize/impl/HessianSerializer.java of the component xxl-rpc Listener. The manipulation results in deserialization. The attack may be performed from remote. The exploit is now public and may be used. The project closed the issue report as "not planned" without any further explanation. High CVSS 7.3 14/08 CVE-2026-27380Editor PHP Object Injection in Car Rental Manager <= 1.3.9 versions. High CVSS 7.2 13/08 CVE-2026-28149Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions. Critical CVSS 9.8 13/08 CVE-2026-28176Unauthenticated PHP Object Injection in Booking Activities <= 1.18.4 versions. High CVSS 8.8 13/08 CVE-2026-66256** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig. This issue affects Apache Shindig: all versions. Users with access to the Shindig REST API can send specially-crafted requests to trigger arbitrary code execution on the server. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.NVD analysis in progress High CVSS 7.2 13/08 CVE-2026-58076Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and instantiating it with arguments from the same blob, with no restriction on what could be imported. An operator's `executor_config` reaches that branch, so a Dag author could place a value there that causes an arbitrary callable to be imported and invoked -- for example `subprocess.check_output`, or `builtins.eval` on the `builtins`-prefixed variant. The code runs in the **Scheduler**, which reconstructs serialized Dags in its normal loop with no request involved, and in the **API server**, on any authenticated read of the Dag such as `GET /api/v2/dags/{dag_id}/details`. Both are components the Airflow security model states must never execute Dag-author code, and both hold the metadata database credentials and the JWT signing secret. No non-default configuration is required. This is a **different sink from CVE-2026-33264**, which covered only the trigger branch of the same deserializer: deployments that upgraded in response to that advisory are still affected through the exception branch and must upgrade again. Users are advised to upgrade to apache-airflow 3.3.1 or later, which restricts the imported class to a subclass of `BaseException`.Apache Airflow High CVSS 8.8 12/08 CVE-2026-67260Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deserializes the task instance's `next_kwargs` without an allow-list, so a Dag author — who controls that value through the task execution API — can cause an arbitrary module import and object instantiation inside the scheduler process, or terminate the scheduler job. No non-default configuration is required: the sweep runs unconditionally every 15 seconds, and the default `allowed_deserialization_classes` setting does not cover this code path. Versions before 3.3.0 are not affected, because human-in-the-loop tasks deferred onto the triggerer instead. This is a different code path from CVE-2026-58076, which covers the same unguarded exception-node deserialization reached elsewhere — deployments that applied that fix must upgrade for this issue as well. Users are advised to upgrade to apache-airflow 3.3.1 or later.Apache Airflow High CVSS 7.3 12/08 CVE-2026-67579Deserialization of Untrusted Data vulnerability in ash-project ash allows an unauthenticated attacker to inject a filter expression through a forged keyset pagination cursor, resulting in SQL injection or code execution depending on the data layer. Read actions with keyset pagination decode the client-supplied page[:after] or page[:before] cursor in decode_values/2 in lib/ash/page/keyset.ex using non_executable_binary_to_term/2 with [:safe]. That guard blocks new atoms, funs, and ports, but not a struct built from atoms already interned in a running Ash application, so a decoded %Ash.Query.Call{} expression survives and is spliced into the keyset filter as a comparison value in do_filters/4 and evaluated. Because the cursor bypasses the Ash.Expr macro, the runtime never applies the private?/public? gate that would otherwise reject it. On AshPostgres the injected fragment is inlined into the SQL query; on the ETS and Simple data layers it is evaluated in-process as an arbitrary function call. This issue affects ash: from 1.17.0 before 3.31.3.Ash-hq Ash Framework High CVSS 7.5 12/08 CVE-2026-67587Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback path. Because `SyncCallback` is itself an Airflow class it passes the default `allowed_deserialization_classes` allow-list, so tightening that setting does not help. A Dag author — who controls a task instance's `next_kwargs` through the task execution API — can therefore cause an arbitrary module to be imported inside the scheduler process, when the scheduler's `awaiting_input` timeout sweep deserializes that value. No non-default configuration is required; the sweep runs unconditionally. Versions before 3.3.0 are not affected: the class existed, but the scheduler sweep that reaches it did not. This is a separate code path from CVE-2026-58076 and CVE-2026-67260, which cover different gadgets reaching deserialization — applying either of those fixes does not address this one. Users are advised to upgrade to apache-airflow 3.3.1 or later.Apache Airflow High CVSS 8.8 12/08 CVE-2026-73325Fujitsu Research's OneCompression library 1.2.0 contains an unsafe deserialization vulnerability that allows attackers to execute arbitrary code by supplying a crafted model.pt checkpoint file, as QuantizedModelLoader.load_quantized_model_pt() unconditionally calls torch.load with weights_only=False, invoking Python's pickle machinery during deserialization. Attackers can embed malicious __reduce__ methods in a crafted model checkpoint to execute arbitrary Python code, including system commands, when the library loads the file from a caller-selected model directory.NVD analysis in progress High CVSS 7.8 12/08 CVE-2026-15555A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session data via the JBoss Marshalling River unmarshaller with no class filtering — enabling RCE via deserialization gadget chains on every cluster node.NVD analysis in progress High CVSS 8.8 11/08 CVE-2026-17061A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2026 could lead to an unauthenticated remote code execution.NVD analysis in progress Critical CVSS 10 11/08 CVE-2026-18634An insecure handling of serialized objects vulnerability was found in the one of the service of GMS application 9.5.1 (Build 9510.1044) and earlier versions. A local attacker with the ability to interact with the service could exploit this behavior to perform unauthorized actions through the affected component.NVD analysis in progress High CVSS 8.4 11/08 CVE-2026-48397Lightroom Classic is affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.Adobe Lightroom High CVSS 8.6 11/08 CVE-2026-59124Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.Microsoft Windows App Critical CVSS 9.8 11/08 CVE-2026-63514Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.Microsoft Sharepoint Server High CVSS 8.8 11/08 CVE-2026-64901Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.Microsoft Sharepoint Server High CVSS 8.8 11/08 CVE-2026-65658Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.Microsoft Sharepoint Server High CVSS 8.8 11/08 CVE-2026-65663Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.Microsoft Sharepoint Server High CVSS 8.8 11/08 CVE-2026-65665Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.Microsoft Sharepoint Server High CVSS 8.8 11/08 CVE-2026-65815Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.Microsoft Dynamics 365 High CVSS 8.8 11/08 CVE-2026-66805Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.Microsoft Sharepoint Server High CVSS 8.8 11/08 CVE-2026-66808Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.Microsoft Sharepoint Server High CVSS 8.8 11/08 CVE-2026-70321Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.Microsoft Sharepoint Server High CVSS 8.8 11/08 CVE-2026-18948A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'dill' library. This allows a remote attacker to store a malicious UDF, leading to unauthenticated arbitrary code execution on the feature server in default configurations. An authenticated attacker can also achieve arbitrary code execution on the registry server by bypassing authorization checks during deserialization. This vulnerability can result in cross-tenant data access and lateral movement within the system.NVD analysis in progress Critical CVSS 9.9 10/08 CVE-2026-16267The Newsletters WordPress plugin before 4.16 does not restrict the classes allowed when unserialising a value taken from a public form submission, allowing unauthenticated attackers to inject arbitrary PHP objects.NVD analysis in progress High CVSS 8.1 08/08 CVE-2026-16258The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via another installed Ajax Search Lite WordPress plugin before 4.14.5 or , this can be leveraged to achieve Remote Code Execution.NVD analysis in progress Critical CVSS 9.8 07/08 CVE-2026-50515Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.Microsoft Azure Service Bus Critical CVSS 9.9 07/08 CVE-2026-68772ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component that allows attackers with write access to a shared artifact store to execute arbitrary code by planting a malicious pickle file. Attackers can replace a stored artifact.pkl file with a crafted cloudpickle payload containing a malicious __reduce__ method, which executes arbitrary system commands when any user or pipeline materializes the artifact through the unsanitized cloudpickle.load() call in cloudpickle_materializer.py.NVD analysis in progress High CVSS 8 07/08 CVE-2026-71558Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic smart-pointer deserialization, causing an object of an incompatible type to be treated as the declared base type. This may result in undefined behavior and potentially lead to denial of service or arbitrary code execution. Users are recommended to upgrade to Apache Fory 1.5.0, which fixes this issue. Applications not using Apache Fory C++ polymorphic smart-pointer deserialization are not affected.Apache Fory Critical CVSS 9.8 07/08 CVE-2026-71559Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic. This issue affects Apache Fory: from 0.16.0 before 1.5.0.  Users of other language implementations are not affected. Users are recommended to upgrade to version 1.5.0, which fixes the issue.Apache Fory High CVSS 7.5 07/08 CVE-2026-71560Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deserializing structs containing tagged integer fields. A crafted input payload may trigger an out-of-bounds heap read in the tagged integer fast-path deserializer, potentially causing information disclosure or denial of service. Users are recommended to upgrade to Apache Fory 1.5.0, which fixes this issue. Applications that do not use Apache Fory C++ or do not use tagged integer fields are not affected.Apache Fory Critical CVSS 9.1 07/08 CVE-2026-28139Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions. Critical CVSS 9.8 06/08 CVE-2026-65549Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions. High CVSS 7.2 06/08 CVE-2026-65552Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions. Critical CVSS 9.8 06/08 CVE-2026-65556Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions. Critical CVSS 9.8 06/08 CVE-2026-65571Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions. Critical CVSS 9.8 06/08 CVE-2026-65572Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions. Critical CVSS 9.8 06/08 CVE-2026-65573Unauthenticated PHP Object Injection in Abelle <= 1.22 versions. Critical CVSS 9.8 06/08 CVE-2026-65574Unauthenticated PHP Object Injection in Abogado <= 1.18 versions. Critical CVSS 9.8 06/08 CVE-2026-65575Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions. Critical CVSS 9.8 06/08 CVE-2026-65576Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions. Critical CVSS 9.8 06/08 CVE-2026-65577Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions. Critical CVSS 9.8 06/08 CVE-2026-65578Unauthenticated PHP Object Injection in Agora <= 1.9 versions. Critical CVSS 9.8 06/08 CVE-2026-65579Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions. Critical CVSS 9.8 06/08 CVE-2026-65581Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions. Critical CVSS 9.8 06/08 CVE-2026-66909Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a malicious serialized object, leading to denial of service or, if a suitable gadget class is on the classpath, remote code execution. The fix disables ObjectMessage deserialization by default, with a configuration switch to re-enable it if needed. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.Apache Cxf Critical CVSS 9.8 06/08 CVE-2026-61484** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.Apache Lucy Critical CVSS 9.8 05/08 CVE-2026-63077In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocolJetBrains TeamCity Critical CVSS 9.8 05/08 CVE-2026-70426In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-200 class filter is not applied to classes resolved via a fallback path in the Remoting deserialization implementation, allowing agent processes, code running on agents, and attackers with Agent/Connect permission to bypass the JEP-200 deserialization filter for classes on the Jenkins core classpath.NVD analysis in progress Critical CVSS 9 05/08 CVE-2026-71281Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft/tuners/lora/corda.py lines ~102 and ~163, and src/peft/tuners/lora/loraga.py line ~101) call torch.load on config-specified cache/covariance files without weights_only=True, bypassing peft's own safe-loading wrapper used elsewhere in the codebase.NVD analysis in progress High CVSS 8.8 05/08 CVE-2026-71294Cotonti CMS's Comments plugin deserializes user-supplied data without restricting the classes that may be instantiated. In plugins/comments/controllers/actions/CreateAction.php, a POST parameter obtained via (trim-only sanitization) is passed to with no restriction, reachable by any member with write access to comments (the default setting in plugins/comments/comments.setup.php).NVD analysis in progress High CVSS 7.6 05/08 CVE-2026-47623NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to denial of service and data tampering.Nvidia Dynamo High CVSS 8.2 04/08 CVE-2026-69098kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type__ field. Attackers can exploit this to override the __type__ field with subprocess.check_output and arbitrary arguments, achieving remote code execution with application process privileges.NVD analysis in progress Critical CVSS 9.8 04/08 CVE-2026-70554MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie directly to unserialize() without validation or class allowlisting. Attackers can craft a malicious serialized PHP object payload delivered in a single HTTP request to trigger magic methods during object graph reconstruction, enabling property-oriented programming attacks or remote code execution via available gadget chains such as those targeting SoapClient or Imagick extensions.NVD analysis in progress Critical CVSS 9.8 04/08 CVE-2025-15672The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects, which could lead to remote code execution when a suitable gadget chain is present via other installed code.NVD analysis in progress High CVSS 8.1 03/08 CVE-2026-18642Deserialization of untrusted data vulnerability in TUBITAK BILGEM Software Technologies Research Institute eta-otp-lock allows Object Injection. This issue affects eta-otp-lock: before 1.0.4.NVD analysis in progress High CVSS 7.8 03/08 CVE-2026-3245A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.NVD analysis in progress High CVSS 7.5 03/08 CVE-2026-12720The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated users can store, leading to PHP Object Injection that is triggered when an administrator later reviews the stored data. With a suitable gadget chain present on the site (via another installed Kirki WordPress plugin before 6.0.13, , or an outdated WordPress version), this could be leveraged to perform a variety of attacks, such as remote code execution.NVD analysis in progress High CVSS 7.5 31/07 CVE-2026-68771ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserialization. Attackers can upload a malicious shard_*.pkl file via the unauthenticated POST /upload/image endpoint and then queue a workflow graph via POST /prompt referencing the uploaded file, causing torch.load to deserialize the attacker-controlled pickle payload using __reduce__ and execute arbitrary commands as the ComfyUI process user.NVD analysis in progress Critical CVSS 9.8 31/07 CVE-2026-11536IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector.Ibm Websphere Application Server High CVSS 8.5 30/07 CVE-2026-12118IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data.Ibm Webmethods Integration Critical CVSS 9.8 30/07 CVE-2026-1360The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 14.5.0 This is due to the `bp_unserialize_profile_field()` function using `@unserialize()` without the `allowed_classes` parameter on user-controlled XProfile field data. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary PHP objects via XProfile textbox fields, which could lead to remote code execution if a suitable POP chain is available in the WordPress environment. High CVSS 7.5 30/07 CVE-2026-15969SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitrary command execution through crafted base64-encoded pickle payloads.Lmsys Sglang Critical CVSS 9.8 30/07 CVE-2026-15976SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically within the /update_weights_from_disk, where torch.load(..., weights_only=False) fallback enables pickle deserialization of .bin files.Lmsys Sglang Critical CVSS 9.8 30/07 CVE-2026-57859e107 prior to version 2.3.8 contains a code execution vulnerability in the e_array deserialization handler that allows an attacker with out-of-band database write access to execute arbitrary PHP code by storing a crafted payload in the user_prefs column. The e_array::unserialize() function in e107_handlers/core_functions.php performs only a prefix check for the string 'array' before passing the stored value to eval(), causing automatic PHP execution whenever the affected user's preferences are materialized through e_user_pref::load(). High CVSS 7.5 30/07

The 100 most recent.

Type at least two characters.

navigate open esc dismiss