Tag

#deserialization

9 stories taggeddeserialization.

A video player interface rendered in a web browser window, displaying code injection points where serialized data is being deserialized without validation, with
Vulnerabilities

Two unpatched flaws in Kaltura's video player let attackers read files and run code

CERT/CC has gone public with a pair of bugs in Kaltura's mwEmbed library. Both trace back to the same old web-security sin: trusting user-supplied serialized data.

3 min read
An industrial control room with SCADA system displays showing pipeline and manufacturing equipment monitoring, a security alert panel highlighting a code execut
Vulnerabilities

AVEVA warns of code-execution flaw in Enterprise SCADA software used across pipelines and manufacturing

A high-severity deserialization bug lets an authenticated operator run code inside the industrial control system. AVEVA has shipped patches for every supported release.

4 min read
A close-up of a developer's desk with multiple monitors displaying code and warning alerts, with a red notification banner visible on the central screen, urgent
Vulnerabilities

Hackers Are Actively Exploiting a Critical Flaw in JetBrains TeamCity

A software tool used by thousands of development teams has a severe security hole that attackers are already using. The US government is giving federal agencies three days to fix it.

3 min read
Server room with multiple rack-mounted machines and blinking indicator lights, highlighting one unit with a red alert status, code scrolling across a monitoring
Vulnerabilities

Hackers Hit Unpatched Fastjson Bug in Spring Boot Apps, No Fix Yet

CVE-2026-16723 lets attackers run code on vulnerable Java servers without a password. Alibaba scores it 9.0. No patch is available.

3 min read
Illustration: a dimly lit enterprise server room with rack-mounted servers glowing amber
Vulnerabilities

CISA Flags SharePoint Deserialization Bug CVE-2026-45659 as Actively Exploited

The RCE flaw joins KEV with a three-week federal patch deadline. Attribution details remain thin.

3 min read
Illustration: a sprawling industrial manufacturing floor at night
Vulnerabilities

Active Exploitation Hits PTC Windchill as Attackers Drop Web Shells on PLM Systems

A critical deserialization flaw in software used by Boeing, Lockheed Martin, and BMW is drawing threat actors toward some of the most sensitive intellectual property in global manufacturing.

2 min read
Illustration: a circuit board with glowing green data pathways running across its surface
AI Security

Silent RCE in Hugging Face Transformers Hides Behind a Single Config Field

CVE-2026-4372 lets an attacker own any machine that loads a poisoned model. No warnings, no prompts, no trace. The trust_remote_code flag turned out to be decorative.

3 min read
Illustration: a dimly lit e-commerce warehouse server rack with a single red status LED glowing
Vulnerabilities

CISA Flags Magento Cache Extension Bug as Actively Exploited

CVE-2026-45247, an unsafe deserialization flaw in Mirasvit Cache Warmer, lands in KEV after in-the-wild abuse against Magento storefronts.

3 min read
Illustration: A digital shield protecting a SharePoint server
Vulnerabilities

SharePoint's latest RCE bug hands attackers the keys with no extra paperwork

CVE-2026-45659 is a deserialization flaw that doesn't ask for much, and that's exactly why Microsoft is shipping fixes across every supported SharePoint Server build.

2 min read
© 2026 Threat Vectr