Tag

#deserialization

8 stories taggeddeserialization.

Full-frame edge-to-edge 16:9 photoreal editorial image of a dimly lit enterprise server room with rack-mounted servers glowing amber, a single open maintenance
Vulnerabilities

AVEVA warns of code-execution flaw in Enterprise SCADA software used across pipelines and manufacturing

A high-severity deserialization bug lets an authenticated operator run code inside the industrial control system. AVEVA has shipped patches for every supported release.

4 min read
Full-frame edge-to-edge photoreal editorial image of a dimly lit server rack in a data centre, with amber warning lights glowing on network switches, a soft red
Vulnerabilities

Hackers Are Actively Exploiting a Critical Flaw in JetBrains TeamCity

A software tool used by thousands of development teams worldwide has a severe security hole that attackers are already using. The US government is telling federal agencies they have three days to fix it.

3 min read
A digital shield protecting a SharePoint server
Vulnerabilities

Hackers Hit Unpatched Fastjson Bug in Spring Boot Apps, No Fix Yet

CVE-2026-16723 lets attackers run code on vulnerable Java servers without a password. Alibaba scores it 9.0. No patch is available.

4 min read
Vulnerabilities

CISA Flags SharePoint Deserialization Bug CVE-2026-45659 as Actively Exploited

The RCE flaw joins KEV with a three-week federal patch deadline. Attribution details remain thin.

2 min read
Vulnerabilities

Active Exploitation Hits PTC Windchill as Attackers Drop Web Shells on PLM Systems

A critical deserialization flaw in software used by Boeing, Lockheed Martin, and BMW is drawing threat actors toward some of the most sensitive intellectual property in global manufacturing.

2 min read
AI Security

Silent RCE in Hugging Face Transformers Hides Behind a Single Config Field

CVE-2026-4372 lets an attacker own any machine that loads a poisoned model — no warnings, no prompts, no trace. The trust_remote_code flag didn't help.

2 min read
Vulnerabilities

CISA Flags Magento Cache Extension Bug as Actively Exploited

CVE-2026-45247, an unsafe deserialization flaw in Mirasvit Cache Warmer, lands in KEV after in-the-wild abuse against Magento storefronts.

2 min read
Vulnerabilities

SharePoint's latest RCE bug hands attackers the keys with no extra paperwork

CVE-2026-45659 is a deserialization flaw that doesn't ask for much — and that's exactly why Microsoft is shipping fixes across every supported SharePoint Server build.

2 min read
© 2026 Threat Vectr