Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2614+ Articles
162+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
All tags
34 articles

#Deserialization

All CosmicBytez Labs articles tagged #Deserialization, across news, security advisories, how-to guides, and projects.

  • SecurityAug 26, 2026

    CISA Adds Ajax.NET Professional Deserialization RCE to KEV Catalog

    CISA added CVE-2021-23758, a critical unauthenticated deserialization RCE in the end-of-life AjaxPro.2 library, to its Known Exploited Vulnerabilities catalog.

  • SecurityAug 23, 2026

    CVE-2026-0551: PHP Object Injection in PPWP – Password Protect Pages WordPress Plugin

    PPWP WordPress plugin up to 1.9.18 allows contributor-level PHP object injection via deserialization, enabling RCE on affected sites.

  • SecurityAug 19, 2026

    Critical Deserialization Flaw in Seroval JS Library (CVE-2026-59940)

    Seroval < 1.5.3 allows attacker-controlled JSON Promise nodes to bypass reference validation in fromJSON(), enabling object forgery. CVSS 9.8.

  • SecurityAug 17, 2026

    WordPress ARForms Plugin Critical PHP Object Injection — CVE-2024-13784

    A critical unauthenticated PHP object injection flaw in the ARForms WordPress plugin (CVSS 9.8) allows arbitrary code execution via deserialization.

  • SecurityAug 11, 2026

    CVE-2026-18948: Feast Feature Store RCE via Unsafe Deserialization

    A critical CVSS 9.9 vulnerability in the Feast ML feature store allows unauthenticated remote code execution through malicious user-defined functions serialized with the Python dill library and stored in the feature registry.

  • SecurityAug 7, 2026

    CVE-2026-28139: Critical PHP Object Injection in Ajax Search Lite

    A CVSS 9.8 unauthenticated PHP object injection flaw in Ajax Search Lite <= 4.14.4 exposes 80,000+ WordPress sites to potential remote code execution via POP chain gadgets.

  • SecurityAug 5, 2026

    CVE-2026-63077: JetBrains TeamCity Deserialization RCE Added to CISA KEV

    JetBrains TeamCity contains a critical deserialization of untrusted data vulnerability allowing unauthenticated remote code execution via the agent polling protocol. CISA has added it to the Known Exploited Vulnerabilities catalog.

  • SecurityAug 1, 2026

    CVE-2026-68771: ComfyUI Unsafe Pickle Deserialization Enables Unauthenticated RCE

    ComfyUI v0.23.0 contains a critical unsafe deserialization vulnerability in the LoadTrainingDataset node. Unauthenticated attackers can upload a crafted pickle file and trigger arbitrary Python code execution. CVSS 9.8.

  • SecurityJul 29, 2026

    CVE-2026-14512: IBM WebSphere Pre-Auth Deserialization Allows RCE

    A critical pre-authentication unsafe deserialization flaw (CVSS 9.8) in IBM WebSphere Application Server 8.5 and 9.0 allows remote attackers to bypass authentication or execute arbitrary code.

  • SecurityJul 28, 2026

    CVE-2026-11756: Critical Unauthenticated RCE in Dassault 3DEXPERIENCE

    A CVSS 10.0 deserialization vulnerability in the 3DEXPERIENCE Station Launcher App allows unauthenticated attackers to execute arbitrary code on any affected workstation — no credentials, no interaction required.

  • SecurityJul 26, 2026

    CVE-2026-15962: PHP Object Injection in Fluent Forms Pro (CVSS 8.8)

    A high-severity PHP Object Injection vulnerability in the Fluent Forms Pro Add On Pack plugin for WordPress allows authenticated attackers with Subscriber-level access to inject PHP objects and potentially achieve remote code execution via a POP chain in versions up to 6.2.6.

  • SecurityJul 24, 2026

    fastjson RCE Without Gadget or AutoType — CVE-2026-16723

    A critical remote code execution flaw in fastjson 1.2.68–1.2.83 requires no AutoType enablement and no classpath gadget, making it exploitable on...

  • SecurityJul 23, 2026

    CVE-2026-50522: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

    Microsoft SharePoint contains a critical deserialization of untrusted data vulnerability allowing unauthenticated attackers to execute arbitrary code over...

  • SecurityJul 22, 2026

    CVE-2026-64606: Apache Fury Critical Deserialization Flaw (CVSS 9.8)

    A critical deserialization vulnerability in Apache Fury allows attackers to bypass class-registration checks during Java lambda deserialization, enabling...

  • SecurityJul 14, 2026

    CVE-2026-57433: Perl Storable Signed Integer Overflow in SX_HOOK Deserialization

    A CVSS 9.8 signed integer overflow in Perl's Storable module (before 3.41) allows a crafted SX_HOOK record to wrap an I32_MAX item count to -1, corrupting...

  • SecurityJul 12, 2026

    CVE-2026-58281: Microsoft Edge RCE via Deserialization of Untrusted Data

    A high-severity deserialization vulnerability in Microsoft Edge (Chromium-based) allows unauthorized network attackers to execute arbitrary code. CVSS 8.3...

  • SecurityJul 8, 2026

    CVE-2026-33264: Apache Airflow Scheduler RCE via DAG Deserialization

    A critical deserialization flaw in Apache Airflow allows malicious DAG authors to execute arbitrary code on the Scheduler and API Server, scoring CVSS...

  • SecurityJul 5, 2026

    CVE-2026-14637: PHP Deserialization RCE in CodeIgniter Ecommerce Bootstrap Shopping Cart

    A high-severity PHP deserialization vulnerability in the kirilkirkov Ecommerce-CodeIgniter-Bootstrap allows attackers to inject malicious serialized...

  • SecurityJun 3, 2026

    CVE-2026-47065: Java Deserialization Filter Bypass via resolveProxyClass (CVSS 9.8)

    A CVSS 9.8 critical Java deserialization vulnerability allows attackers to bypass ObjectInputFilter via TC_PROXYCLASSDESC, circumventing acceptMatchers…

  • SecurityMay 30, 2026

    CVE-2026-10042: manga-image-translator RCE via Unsafe Python Deserialization

    A critical CVSS 9.8 remote code execution vulnerability in manga-image-translator allows unauthenticated attackers to execute arbitrary commands by...

  • NewsMay 26, 2026

    Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell

    A hardcoded machineKey value in KnowledgeDeliver's configuration enabled ViewState deserialization attacks leading to remote code execution and web shell.

  • SecurityMay 22, 2026

    CVE-2026-48207: Apache Fury PyFury Deserialization RCE

    A critical deserialization vulnerability in Apache Fury's Python library PyFury allows attackers to bypass DeserializationPolicy validation hooks via the...

  • SecurityMay 20, 2026

    CVE-2026-7637: WordPress Boost Plugin PHP Object Injection

    The Boost plugin for WordPress versions up to 2.0.3 is vulnerable to PHP Object Injection via deserialization of the STYXKEY-BOOST_USER_LOCATION cookie,...

  • SecurityMay 19, 2026

    CVE-2026-7301: SGLang ROUTER Socket Exposes Unsafe

    A critical CVSS 9.8 vulnerability in SGLang's multimodal AI runtime scheduler binds its ROUTER socket to 0.0.0.0 by default and passes incoming messages...

  • SecurityMay 2, 2026

    CVE-2026-42779: Critical Apache MINA Deserialization Class

    An incomplete fix for CVE-2026-41635 leaves Apache MINA 2.1.x and 2.2.x branches exposed to a critical deserialization bypass via...

  • SecurityMay 1, 2026

    Apache MINA Incomplete Deserialization Patch Leaves 2.1.X

    Apache MINA versions 2.1.X and 2.2.X remain vulnerable to unauthenticated remote code execution because the fix for CVE-2026-41409 was never backported,...

  • SecurityApr 28, 2026

    CVE-2026-40860: Apache Camel JMS Unsafe ObjectMessage

    Apache Camel's JmsBinding class in camel-jms and camel-sjms deserializes incoming JMS ObjectMessage payloads via javax.jms.ObjectMessage.getObject()...

  • SecurityApr 28, 2026

    CVE-2026-41635: Apache MINA Class Allowlist Bypass Enables

    Apache MINA's AbstractIoBuffer.resolveClass() contains a branch for static classes and primitive types that skips allowlist validation entirely, letting...

  • SecurityApr 24, 2026

    CVE-2026-26210: KTransformers Unsafe Deserialization RCE

    KTransformers through version 0.5.3 contains a critical unsafe deserialization vulnerability in its balance_serve backend mode, where an unauthenticated...

  • NewsApr 18, 2026

    Critical Flaw in protobuf.js Library Enables JavaScript

    A critical remote code execution vulnerability in protobuf.js, the widely used JavaScript implementation of Google's Protocol Buffers, has been disclosed...

  • NewsMar 25, 2026

    PTC Warns of Imminent Threat from Critical Windchill

    PTC is warning customers of an imminent exploit threat against a critical deserialization vulnerability in Windchill and FlexPLM — CVE-2026-4681, CVSS...

  • SecurityMar 19, 2026

    CVE-2026-25449: Critical Object Injection in Shinetheme

    A CVSS 9.8 deserialization vulnerability in the Shinetheme Traveler WordPress plugin allows unauthenticated remote attackers to inject arbitrary PHP...

  • SecurityMar 18, 2026

    CVE-2026-25769: Wazuh Critical RCE via Insecure

    A critical remote code execution vulnerability (CVSS 9.1) in Wazuh versions 4.0.0–4.14.2 allows an attacker with access to a worker node to achieve root...

  • SecurityFeb 5, 2026

    SolarWinds Web Help Desk RCE Vulnerability Added to CISA KEV

    Critical deserialization vulnerability in SolarWinds Web Help Desk enables unauthenticated remote code execution. CISA confirms active exploitation.