← Back to News Iceland Security Dashboard Browse all tags
deserialization

Insecure Deserialization

CVEs in this class (60)

CVE-2026-45247 🚨 CVSS 9.8 Mirasvit / Mirasvit Full Page Cache Warmer
CVE-2026-45247 is a critical remote code execution vulnerability in Mirasvit Full Page Cache Warmer for Magento 2 versions prior to 1.11.12, classified as CWE-5…
CVE-2025-26399 🚨 SolarWinds / Web Help Desk
SolarWinds Web Help Desk contains a critical unauthenticated AjaxProxy deserialization vulnerability (CVE-2025-26399) allowing remote code execution, serving as…
CVE-2026-58644 🚨 Microsoft / SharePoint
CVE-2026-58644 is a critical remote code execution vulnerability in Microsoft Office SharePoint caused by the deserialization of untrusted data. The vulnerabili…
CVE-2026-50522 🚨 Microsoft / SharePoint
CVE-2026-50522 is a critical deserialization vulnerability (CWE-502) in Microsoft Office SharePoint that allows unauthorized remote code execution over a networ…
CVE-2025-59287 🚨 Microsoft / Windows
CVE-2025-59287 is a critical deserialization vulnerability (CWE-502) in Windows Server Update Service affecting Microsoft Windows, allowing unauthorized remote …
CVE-2026-20963 🚨 Microsoft / SharePoint
CVE-2026-20963 is a critical deserialization vulnerability (CWE-502) in Microsoft Office SharePoint that allows unauthorized remote code execution over a networ…
CVE-2025-5086 🚨 Dassault Systèmes / DELMIA Apriso
CVE-2025-5086 is a critical deserialization vulnerability (CWE-502) in Dassault Systèmes DELMIA Apriso versions from Release 2020 through Release 2025, allowing…
CVE-2025-8875 🚨 N-able / N-Central
CVE-2025-8875 is a high-severity deserialization vulnerability (CWE-502) in N-able N-central versions prior to 2025.3.1, allowing local code execution. The vuln…
CVE-2025-53770 🚨 Microsoft / SharePoint
CVE-2025-53770 is a critical deserialization vulnerability (CWE-502) in on-premises Microsoft SharePoint Server, allowing unauthorized remote code execution wit…
CVE-2025-24016 🚨 Wazuh / Wazuh Server
CVE-2025-24016 is a critical remote code execution vulnerability in Wazuh Server versions 4.4.0 through 4.9.1 caused by unsafe deserialization of DistributedAPI…
CVE-2025-42999 🚨 SAP / NetWeaver
CVE-2025-42999 is a critical deserialization vulnerability in SAP NetWeaver Visual Composer Metadata Uploader, classified under CWE-502. It allows a privileged …
CVE-2025-30406 🚨 Gladinet / CentreStack
Gladinet CentreStack versions through 16.1.10296.56315 are affected by a critical deserialization vulnerability (CVSS 9.0) caused by a hardcoded machineKey in t…
CVE-2019-9875 🚨 Sitecore / CMS and Experience Platform (XP)
CVE-2019-9875 is a high-severity deserialization vulnerability (CWE-502) in the anti-CSRF module of Sitecore CMS and Experience Platform (XP) through version 9.…
CVE-2019-9874 🚨 Sitecore / CMS and Experience Platform (XP)
CVE-2019-9874 is a critical deserialization vulnerability (CWE-502) in Sitecore CMS versions 7.0 to 7.2 and Sitecore XP versions 7.5 to 8.2, allowing unauthenti…
CVE-2024-20953 🚨 Oracle / Agile Product Lifecycle Management (PLM)
CVE-2024-20953 is a high-severity vulnerability (CVSS 8.8) in Oracle Agile PLM version 9.3.6 affecting the Export component. It allows low-privileged attackers …
CVE-2017-3066 🚨 Adobe / ColdFusion
CVE-2017-3066 is a critical Java deserialization vulnerability (CWE-502) in the Apache BlazeDS library affecting Adobe ColdFusion 2016 Update 3 and earlier, Col…
CVE-2025-0994 🚨 Trimble / Cityworks
Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 contain a deserialization vulnerability (CWE-502) that al…
CVE-2025-23006 🚨 SonicWall / SMA1000 Appliances
CVE-2025-23006 is a critical remote code execution vulnerability in SonicWall SMA1000 Appliances affecting the Appliance Management Console and Central Manageme…
CVE-2024-40711 🚨 Veeam / Backup & Replication
CVE-2024-40711 is a critical deserialization vulnerability (CWE-502) in Veeam Backup & Replication that allows unauthenticated remote code execution via malicio…
CVE-2024-28986 🚨 SolarWinds / Web Help Desk
SolarWinds Web Help Desk contains a Java Deserialization vulnerability (CWE-502) that allows for Remote Code Execution. Although initially reported as unauthent…
CVE-2023-29300 🚨 Adobe / ColdFusion
CVE-2023-29300 is a critical deserialization vulnerability in Adobe ColdFusion versions 2018u16 and earlier, 2021u6 and earlier, and 2023.0.0.330468 and earlier…
CVE-2023-38203 🚨 Adobe / ColdFusion
CVE-2023-38203 is a critical deserialization of untrusted data vulnerability (CWE-502) affecting Adobe ColdFusion versions 2018u17 and earlier, 2021u7 and earli…
CVE-2023-40044 🚨 Progress / WS_FTP Server
CVE-2023-40044 is a critical deserialization vulnerability (CWE-502) in Progress WS_FTP Server versions prior to 8.7.4 and 8.8.2, allowing pre-authenticated att…
CVE-2023-26359 🚨 Adobe / ColdFusion
CVE-2023-26359 is a critical deserialization of untrusted data vulnerability (CWE-502) affecting Adobe ColdFusion versions 2018 Update 15 and earlier, as well a…
CVE-2021-39144 🚨 XStream / XStream
CVE-2021-39144 is a critical vulnerability in XStream affecting versions prior to 1.4.18, allowing remote attackers with sufficient rights to execute commands b…
CVE-2020-5741 🚨 Plex / Media Server
CVE-2020-5741 is a high-severity deserialization vulnerability (CWE-502) in Plex Media Server on Windows, allowing remote authenticated attackers to execute arb…
CVE-2022-47986 🚨 IBM / Aspera Faspex
CVE-2022-47986 is a critical remote code execution vulnerability in IBM Aspera Faspex versions 4.4.2 Patch Level 1 and earlier, caused by a YAML deserialization…
CVE-2021-31010 🚨 Apple / iOS, macOS, watchOS
CVE-2021-31010 is a deserialization vulnerability (CWE-502) affecting Apple iOS, macOS, and watchOS, allowing a sandboxed process to circumvent sandbox restrict…
CVE-2021-27852 🚨 Checkbox / Checkbox Survey
CVE-2021-27852 is a critical deserialization of untrusted data vulnerability (CWE-502) in CheckboxWeb.dll affecting Checkbox Survey versions prior to 7. It allo…
CVE-2021-42237 🚨 Sitecore / XP
CVE-2021-42237 is a critical insecure deserialization vulnerability (CWE-502) affecting Sitecore XP versions 7.5 Initial Release through 8.2 Update-7, allowing …
CVE-2018-0147 🚨 Cisco / Secure Access Control System (ACS)
CVE-2018-0147 is a critical remote code execution vulnerability in Cisco Secure Access Control System (ACS) prior to version 5.8 patch 9, caused by insecure Jav…
CVE-2026-69836 🚨 Microsoft / Entra ID
CVE-2026-69836 is a critical deserialization vulnerability in Microsoft Entra ID that allows unauthorized attackers to execute code over a network. The vulnerab…
CVE-2017-12149 🚨 Red Hat / JBoss Application Server
CVE-2017-12149 is a critical remote code execution vulnerability in the ReadOnlyAccessFilter of the HTTP Invoker in JBoss Application Server, specifically as sh…
CVE-2017-9805 🚨 Apache / Struts
CVE-2017-9805 is a critical deserialization vulnerability in the Apache Struts REST Plugin affecting versions 2.1.1 through 2.3.33 and 2.5.x through 2.5.12. The…
CVE-2018-4939 🚨 Adobe / ColdFusion
CVE-2018-4939 is a critical deserialization vulnerability in Adobe ColdFusion Update 5 and earlier, as well as ColdFusion 11 Update 13 and earlier, allowing arb…
CVE-2020-7961 🚨 Liferay / Liferay Portal
CVE-2020-7961 is a critical remote code execution vulnerability in Liferay Portal versions prior to 7.2.1 CE GA2, classified as deserialization of untrusted dat…
CVE-2020-2555 🚨 Oracle / Multiple Products
CVE-2020-2555 is a critical vulnerability in Oracle Coherence affecting versions 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, and 12.2.1.4.0, classified under CWE-502 for D…
CVE-2015-4852 🚨 Oracle / WebLogic Server
CVE-2015-4852 is a critical remote code execution vulnerability in Oracle WebLogic Server versions 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0, classified under …
CVE-2019-18935 🚨 Progress / Telerik UI for ASP.NET AJAX
CVE-2019-18935 is a critical deserialization vulnerability in Progress Telerik UI for ASP.NET AJAX through version 2019.3.1023 that allows remote code execution…
CVE-2021-23758 🚨 Ajax.NET Professional / Ajax.NET Professional
CVE-2021-23758 affects all versions of the Ajax.NET Professional package, allowing attackers to exploit deserialization of untrusted data to achieve remote code…
CVE-2025-10035 🚨 Fortra / GoAnywhere MFT
CVE-2025-10035 is a critical deserialization vulnerability in Fortra's GoAnywhere MFT License Servlet that allows command injection via forged license response …
CVE-2026-45659 🚨 Microsoft / SharePoint Server
CVE-2026-45659 is a high-severity deserialization vulnerability (CWE-502) in Microsoft Office SharePoint that allows authorized attackers to execute code over a…
CVE-2026-43633 CVSS 10.0
HestiaCP versions 1.9.0 through 1.9.4 contain a critical deserialization vulnerability (CWE-502) in the web terminal component. The issue stems from a session f…
CVE-2026-11756 CVSS 10.0
CVE-2026-11756 is a critical deserialization vulnerability (CWE-502) in the Station Launcher App within the 3DEXPERIENCE platform, affecting releases R2023x thr…
CVE-2026-50517 CVSS 9.9
CVE-2026-50517 is a critical deserialization vulnerability (CWE-502) in M365 Copilot that allows an authorized attacker to execute code over a network. The vuln…
CVE-2026-50515 CVSS 9.9 microsoft / azure_service_bus
CVE-2026-50515 is a critical deserialization vulnerability (CWE-502) in Azure Service Bus that allows an authorized attacker to execute code over a network. The…
CVE-2026-12650 CVSS 9.9
CVE-2026-12650 is a critical deserialization vulnerability in Ivanti Neurons for ITSM versions prior to 2026.2, allowing remote authenticated attackers to execu…
CVE-2026-48207 CVSS 9.8 apache / fory
CVE-2026-48207 is a critical deserialization vulnerability in Apache Fory PyFory versions prior to 1.0.0, classified under CWE-502. It allows attackers to bypas…
CVE-2026-7637 CVSS 9.8
CVE-2026-7637 is a critical PHP Object Injection vulnerability in the Boost WordPress plugin versions up to and including 2.0.3, caused by deserialization of un…
CVE-2026-7858 CVSS 9.8
CVE-2026-7858 is a critical deserialization vulnerability (CWE-502) in No Magic Teamwork Cloud and CATIA Magic Collaboration Studio versions 2022x through 2026x…
CVE-2026-47065 CVSS 9.8
CVE-2026-47065 is a critical deserialization vulnerability (CWE-502) in the Java Development Kit involving ObjectInputStream. It allows bypassing acceptMatchers…
CVE-2026-42778 CVSS 9.8 apache / mina
CVE-2026-42778 is a critical deserialization vulnerability in Apache MINA versions 2.1.0 through 2.1.11 and 2.2.0 through 2.2.6. It stems from an incomplete fix…
CVE-2026-42779 CVSS 9.8 apache / mina
CVE-2026-42779 is a critical deserialization vulnerability in Apache MINA versions 2.1.0 through 2.1.11 and 2.2.0 through 2.2.6. It allows arbitrary code execut…
CVE-2026-41409 CVSS 9.8 apache / mina
CVE-2026-41409 is a critical deserialization vulnerability in Apache MINA versions 2.0.0 through 2.0.27, 2.1.0 through 2.1.10, and 2.2.0 through 2.2.5. The flaw…
CVE-2026-40860 CVSS 9.8 apache / camel
CVE-2026-40860 is a critical deserialization vulnerability (CWE-502) in Apache Camel versions 3.0.0 through 4.20.0, affecting components such as camel-jms, came…
CVE-2026-41635 CVSS 9.8 apache / mina
Apache MINA versions 2.0.0 through 2.0.27, 2.1.0 through 2.1.10, and 2.2.0 through 2.2.5 are vulnerable to arbitrary code execution due to insufficient validati…
CVE-2026-35300 CVSS 9.8 oracle / weblogic_server
Oracle WebLogic Server versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are affected by a critical deserialization vulnerability (CWE-502) in the Cor…
CVE-2026-8024 CVSS 9.8
CVE-2026-8024 is a critical deserialization vulnerability (CWE-502) affecting ibaPDA and ibaDatCoordinator, allowing remote, unauthenticated attackers to gain f…
CVE-2026-3296 CVSS 9.8
CVE-2026-3296 is a critical PHP Object Injection vulnerability in Everest Forms for WordPress versions up to 3.4.3, caused by unsafe deserialization of untruste…
CVE-2026-43867 CVSS 9.8 apache / camel
CVE-2026-43867 is a critical deserialization vulnerability (CWE-502) in the Apache Camel PQC Component affecting versions 4.18.0 through 4.18.2 and 4.19.0 throu…

Top vendors in this class

Top MITRE ATT&CK techniques in this class