← Back to News Iceland Security Dashboard Browse all tags
deserialization

Insecure Deserialization

CVEs in this class (60)

CVE-2025-59287 🚨 Microsoft / Windows
CVE-2025-59287 is a critical vulnerability in Microsoft Windows Server Update Service (WSUS) involving the deserialization of untrusted data, classified under C…
CVE-2025-8875 🚨 N-able / N-Central
CVE-2025-8875 is a deserialization of untrusted data vulnerability (CWE-502) in N-able N-central versions prior to 2025.3.1, allowing local code execution. The …
CVE-2025-53770 🚨 Microsoft / SharePoint
CVE-2025-53770 is a critical deserialization vulnerability (CWE-502) in on-premises Microsoft SharePoint Server that allows unauthorized remote code execution o…
CVE-2026-20963 🚨 Microsoft / SharePoint
CVE-2026-20963 is a critical deserialization vulnerability (CWE-502) in Microsoft Office SharePoint that allows unauthorized remote code execution over a networ…
CVE-2025-24016 🚨 Wazuh / Wazuh Server
CVE-2025-24016 is a critical remote code execution vulnerability in Wazuh Server versions 4.4.0 through 4.9.1 caused by unsafe deserialization of DistributedAPI…
CVE-2025-42999 🚨 SAP / NetWeaver
CVE-2025-42999 is a critical deserialization vulnerability (CWE-502) in SAP NetWeaver Visual Composer Metadata Uploader, allowing privileged users to upload mal…
CVE-2025-30406 🚨 Gladinet / CentreStack
CVE-2025-30406 is a critical deserialization vulnerability in Gladinet CentreStack versions through 16.1.10296.56315, caused by a hardcoded machineKey that allo…
CVE-2019-9875 🚨 Sitecore / CMS and Experience Platform (XP)
CVE-2019-9875 is a high-severity deserialization vulnerability (CWE-502) in the anti-CSRF module of Sitecore CMS and Experience Platform through version 9.1. It…
CVE-2019-9874 🚨 Sitecore / CMS and Experience Platform (XP)
CVE-2019-9874 is a critical deserialization vulnerability (CWE-502) in Sitecore CMS versions 7.0-7.2 and Sitecore XP versions 7.5-8.2, allowing unauthenticated …
CVE-2024-20953 🚨 Oracle / Agile Product Lifecycle Management (PLM)
CVE-2024-20953 is a high-severity vulnerability (CVSS 8.8) in Oracle Agile PLM version 9.3.6 affecting the Export component. It allows a low-privileged attacker…
CVE-2017-3066 🚨 Adobe / ColdFusion
CVE-2017-3066 is a critical Java deserialization vulnerability (CWE-502) in the Apache BlazeDS library affecting Adobe ColdFusion 2016 Update 3 and earlier, Col…
CVE-2025-0994 🚨 Trimble / Cityworks
CVE-2025-0994 is a deserialization vulnerability in Trimble Cityworks versions prior to 15.8.9 and Cityworks with Office Companion prior to 23.10, allowing auth…
CVE-2025-23006 🚨 SonicWall / SMA1000 Appliances
CVE-2025-23006 is a critical remote code execution vulnerability in SonicWall SMA1000 Appliances affecting the Appliance Management Console and Central Manageme…
CVE-2024-40711 🚨 Veeam / Backup & Replication
CVE-2024-40711 is a critical deserialization vulnerability in Veeam Backup & Replication that allows unauthenticated remote code execution via malicious payload…
CVE-2019-0344 🚨 SAP / Commerce Cloud
CVE-2019-0344 is a critical deserialization vulnerability (CWE-502) in SAP Commerce Cloud versions 6.4 through 1905, allowing arbitrary code execution with Hybr…
CVE-2024-28986 🚨 SolarWinds / Web Help Desk
SolarWinds Web Help Desk contains a Java Deserialization vulnerability (CWE-502) that allows for Remote Code Execution. Although initially reported as unauthent…
CVE-2023-29300 🚨 Adobe / ColdFusion
CVE-2023-29300 is a critical deserialization vulnerability in Adobe ColdFusion versions 2018u16 and earlier, 2021u6 and earlier, and 2023.0.0.330468 and earlier…
CVE-2023-38203 🚨 Adobe / ColdFusion
Adobe ColdFusion versions 2018u17 and earlier, 2021u7 and earlier, and 2023u1 and earlier contain a critical deserialization of untrusted data vulnerability (CW…
CVE-2023-40044 🚨 Progress / WS_FTP Server
CVE-2023-40044 is a critical remote code execution vulnerability in WS_FTP Server versions prior to 8.7.4 and 8.8.2, caused by insecure .NET deserialization in …
CVE-2023-26359 🚨 Adobe / ColdFusion
Adobe ColdFusion versions 2018 Update 15 and earlier, as well as 2021 Update 5 and earlier, contain a critical deserialization of untrusted data vulnerability (…
CVE-2021-39144 🚨 XStream / XStream
CVE-2021-39144 is a vulnerability in XStream that has been added to CISA's Known Exploited Vulnerabilities catalog as of March 10, 2023, with a federal remediat…
CVE-2020-5741 🚨 Plex / Media Server
CVE-2020-5741 is a high-severity deserialization vulnerability (CWE-502) in Plex Media Server on Windows, allowing remote authenticated attackers to execute arb…
CVE-2022-47986 🚨 IBM / Aspera Faspex
IBM Aspera Faspex versions 4.4.2 Patch Level 1 and earlier are vulnerable to a critical remote code execution flaw due to insecure YAML deserialization (CWE-502…
CVE-2021-31010 🚨 Apple / iOS, macOS, watchOS
CVE-2021-31010 is a deserialization vulnerability (CWE-502) affecting Apple iOS, macOS, and watchOS, allowing a sandboxed process to circumvent sandbox restrict…
CVE-2021-27852 🚨 Checkbox / Checkbox Survey
CVE-2021-27852 is a critical deserialization vulnerability (CWE-502) in Checkbox Survey versions prior to 7, allowing unauthenticated remote code execution via …
CVE-2021-42237 🚨 Sitecore / XP
CVE-2021-42237 is a critical insecure deserialization vulnerability (CWE-502) affecting Sitecore XP versions 7.5 Initial Release through 8.2 Update-7, allowing …
CVE-2018-0147 🚨 Cisco / Secure Access Control System (ACS)
CVE-2018-0147 is a critical remote code execution vulnerability in Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9, caused by insecure des…
CVE-2020-2555 🚨 Oracle / Multiple Products
CVE-2020-2555 is a critical vulnerability in Oracle Coherence affecting versions 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, and 12.2.1.4.0, classified under CWE-502 (Dese…
CVE-2015-4852 🚨 Oracle / WebLogic Server
CVE-2015-4852 is a critical remote code execution vulnerability in Oracle WebLogic Server versions 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0, caused by insecur…
CVE-2019-18935 🚨 Progress / Telerik UI for ASP.NET AJAX
CVE-2019-18935 is a critical deserialization vulnerability in Progress Telerik UI for ASP.NET AJAX through version 2019.3.1023 that allows remote code execution…
CVE-2025-49113 🚨 Roundcube / Webmail
CVE-2025-49113 is a critical remote code execution vulnerability in Roundcube Webmail versions before 1.5.10 and 1.6.x before 1.6.11, classified as CWE-502 (Des…
CVE-2025-10035 🚨 Fortra / GoAnywhere MFT
CVE-2025-10035 is a critical deserialization vulnerability in Fortra's GoAnywhere MFT License Servlet, allowing command injection via forged license signatures.…
CVE-2018-2628 🚨 Oracle / WebLogic Server
CVE-2018-2628 is a critical vulnerability in Oracle WebLogic Server affecting versions 10.3.6.0, 12.1.3.0, 12.2.1.2, and 12.2.1.3. It allows unauthenticated att…
CVE-2026-45659 🚨 Microsoft / SharePoint Server
CVE-2026-45659 is a high-severity deserialization vulnerability (CWE-502) in Microsoft Office SharePoint that allows an authorized attacker to execute code over…
CVE-2025-26399 🚨 SolarWinds / Web Help Desk
SolarWinds Web Help Desk contains a critical unauthenticated AjaxProxy deserialization vulnerability (CVE-2025-26399) allowing remote code execution, serving as…
CVE-2026-58644 🚨 Microsoft / SharePoint
CVE-2026-58644 is a critical remote code execution vulnerability in Microsoft Office SharePoint caused by the deserialization of untrusted data. The vulnerabili…
CVE-2026-50522 🚨 Microsoft / SharePoint
CVE-2026-50522 is a critical deserialization vulnerability (CWE-502) in Microsoft Office SharePoint that allows unauthorized remote code execution over a networ…
CVE-2026-43633 CVSS 10.0
HestiaCP versions 1.9.0 through 1.9.4 contain a critical deserialization vulnerability (CWE-502) in the web terminal component. The issue stems from a session f…
CVE-2026-50517 CVSS 9.9
CVE-2026-50517 is a critical deserialization vulnerability (CWE-502) in M365 Copilot that allows an authorized attacker to execute code over a network. The vuln…
CVE-2026-48207 CVSS 9.8 apache / fory
CVE-2026-48207 is a critical deserialization vulnerability in Apache Fory PyFory versions prior to 1.0.0, classified under CWE-502. It allows attackers to bypas…
CVE-2026-7637 CVSS 9.8
CVE-2026-7637 is a critical PHP Object Injection vulnerability in the Boost WordPress plugin versions up to and including 2.0.3, caused by deserialization of un…
CVE-2026-7858 CVSS 9.8
CVE-2026-7858 is a critical deserialization vulnerability (CWE-502) in No Magic Teamwork Cloud and CATIA Magic Collaboration Studio versions 2022x through 2026x…
CVE-2026-47065 CVSS 9.8
CVE-2026-47065 is a critical deserialization vulnerability (CWE-502) in the Java Development Kit involving ObjectInputStream. It allows bypassing acceptMatchers…
CVE-2026-42778 CVSS 9.8 apache / mina
CVE-2026-42778 is a critical deserialization vulnerability in Apache MINA versions 2.1.0 through 2.1.11 and 2.2.0 through 2.2.6. It stems from an incomplete fix…
CVE-2026-42779 CVSS 9.8 apache / mina
CVE-2026-42779 is a critical deserialization vulnerability in Apache MINA versions 2.1.0 through 2.1.11 and 2.2.0 through 2.2.6. It allows arbitrary code execut…
CVE-2026-41409 CVSS 9.8 apache / mina
CVE-2026-41409 is a critical deserialization vulnerability in Apache MINA versions 2.0.0 through 2.0.27, 2.1.0 through 2.1.10, and 2.2.0 through 2.2.5. The flaw…
CVE-2026-40860 CVSS 9.8 apache / camel
CVE-2026-40860 is a critical deserialization vulnerability (CWE-502) in Apache Camel versions 3.0.0 through 4.20.0, affecting components such as camel-jms, came…
CVE-2026-41635 CVSS 9.8 apache / mina
Apache MINA versions 2.0.0 through 2.0.27, 2.1.0 through 2.1.10, and 2.2.0 through 2.2.5 are vulnerable to arbitrary code execution due to insufficient validati…
CVE-2026-35300 CVSS 9.8 oracle / weblogic_server
Oracle WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are affected by a critical deserialization vulnerability (CWE-502) in the Cor…
CVE-2026-8024 CVSS 9.8
CVE-2026-8024 is a critical deserialization vulnerability (CWE-502) affecting ibaPDA and ibaDatCoordinator, allowing remote, unauthenticated attackers to gain f…
CVE-2026-3296 CVSS 9.8
CVE-2026-3296 is a critical PHP Object Injection vulnerability in Everest Forms for WordPress versions up to 3.4.3, caused by unsafe deserialization of untruste…
CVE-2026-43867 CVSS 9.8 apache / camel
CVE-2026-43867 is a critical deserialization vulnerability (CWE-502) in the Apache Camel PQC Component affecting versions 4.18.0 through 4.18.2 and 4.19.0 throu…
CVE-2026-33942 CVSS 9.8 saloon / saloon
CVE-2026-33942 is a critical deserialization vulnerability in Saloon PHP library versions prior to 4.0.0, caused by the unsafe use of PHP's unserialize() with a…
CVE-2026-33264 CVSS 9.8 apache / airflow
CVE-2026-33264 is a critical deserialization vulnerability in Apache Airflow affecting versions prior to 3.3.0, allowing remote code execution via unrestricted …
CVE-2025-60233 CVSS 9.8
CVE-2025-60233 is a critical deserialization vulnerability (CWE-502) in Themeton Zuut versions n/a through 1.4.2, allowing object injection via untrusted data. …
CVE-2025-60237 CVSS 9.8
CVE-2025-60237 is a critical deserialization vulnerability (CWE-502) in Themeton Finag versions n/a through 1.5.0, allowing object injection via untrusted data.…
CVE-2026-25449 CVSS 9.8
CVE-2026-25449 is a critical deserialization vulnerability (CWE-502) affecting shinetheme Traveler versions prior to 3.2.8.1, allowing object injection via untr…
CVE-2026-3060 CVSS 9.8
CVE-2026-3060 is a critical remote code execution vulnerability in SGLang's encoder parallel disaggregation system, rated CVSS 9.8. The flaw allows unauthentica…
CVE-2025-56422 CVSS 9.8
LimeSurvey versions prior to v6.15.0+250623 contain a critical deserialization vulnerability (CWE-502) that allows remote attackers to execute arbitrary code on…
CVE-2026-64606 CVSS 9.8 apache / fory
CVE-2026-64606 is a critical deserialization vulnerability (CWE-502) in Apache Fory versions prior to 1.4.0, allowing class-registration checks to be bypassed d…

Top vendors in this class

Top MITRE ATT&CK techniques in this class