Critical Remote Code Execution Vulnerabilities in SGLangs Runtime
Article Content
- •CVE-2026-7304 and CVE-2026-7301 allow unauthenticated remote code execution in SGLangs runtime.
- •Both vulnerabilities were published on 2026-05-18 and remain unpatched as of 2026-07-16.
- •Exploitation could lead to severe impacts on systems using the SGLangs multimodal generation runtime.
Two critical vulnerabilities, CVE-2026-7304 and CVE-2026-7301, have been identified in the SGLangs multimodal generation runtime. Both vulnerabilities, published on 2026-05-18, allow unauthenticated remote code execution (RCE) under specific conditions. CVE-2026-7304 exploits the --enable-custom-logit-processor option, where Python objects are deserialized without validation. CVE-2026-7301 involves the scheduler's ROUTER socket binding to 0.0.0.0 by default, allowing RCE when exposed to the internet. These vulnerabilities affect systems using SGLangs runtime, potentially impacting a wide range of applications. As of today, no patches or mitigations have been reported, leaving systems vulnerable to exploitation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-7301 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…