Skip to content
Product
Use it
Threat intelligence API
Free key, 70+ endpoints, OpenAPI. The product.
Get started
Pick your stack, make your first call.
Live feed
The console: incidents, filters, entities, search.
Recipes
Runnable examples for the free key.
Free feeds
RSS, ransomware feed, IOC blocklist, MISP — no key.
CLI & agents
tc from a terminal; agent keys with scoped budgets.
The data
Incident records
900 articles a day become ~70 scored incidents.
Dark web
First-party leak-site collection: victims, groups, markets.
Validated IOCs
Indicators with a false-positive gate; STIX, MISP, CSV.
Vulnerabilities
CVEs with EPSS, KEV and exploit status.
Entity graph
Actors, malware, CVEs, companies — pivotable.
For teams
For service providers
Per-client feeds, alerts and branded digests.
Use cases
How teams and builders use the corpus.
About ThreatCluster
What it is and how it is built.
Pricing
Docs
Reference
OpenAPI (Swagger)
Every endpoint, parameter and response model.
ReDoc
The same reference, long-form.
Examples on GitHub
curl, Python and Node quickstarts; daily spec snapshot.
Guides
Quickstart & plans
Key, scopes, budgets, tiers.
Integrations
Splunk, Sentinel, Elastic, agents and terminals, step by step
Export formats
STIX 2.1, MISP, CSV, text.
CLI setup
Install, log in, wire an agent.
No results found
Sign in
Get a free key
No results found
Product
Threat intelligence API
Get started
Live feed
Recipes
Free feeds
CLI & agents
The data
Incident records
Dark web
Validated IOCs
Vulnerabilities
Entity graph
For teams
For service providers
Use cases
About ThreatCluster
Docs
OpenAPI (Swagger)
ReDoc
Examples on GitHub
Quickstart & plans
Integrations
Export formats
CLI setup
Pricing
Contact
Get a free key
Sign in
Back
CWE-502 - Deserialization Of Untrusted Data
CWE Weakness
Threat entity extracted from intelligence sources
Sep 25: 0 mentions
Sep 26: 1 mention
Sep 27: 8 mentions
Sep 28: 6 mentions
Sep 29: 2 mentions
Sep 30: 3 mentions
Oct 1: 0 mentions
Sep 25
Sep 28
Oct 1
Entities
›
cwe
›
CWE-502 - Deserialization Of Untrusted Data
Frequency
235
occurrences
First Seen
April 14, 2026
Last Seen
September 30, 2026
API
Overview
Recent Events
Profile
Profile
MITRE ATT&CK
1 / 2
Threat Actors
ShinyHunters
Shadow-aether-015
Cl0p
Lace Tempest
Chubby Scorpius
FIN11
Graceful Spider
Malware
Cobalt Strike
Tools
Python
Pickle
Hugging Face
ysoserial.net
GitHub Copilot
Docker
Visual Studio
PowerShell
CVEs
CVE-2026-69836
CVE-2026-12569
CVE-2026-35273
CVE-2026-66768
CVE-2026-58240
CVE-2026-44756
CVE-2026-87719
CVE-2026-85706
Campaigns
Oracle EBS campaign
InjectEave Attack
Regions
Germany
France
Brazil
United States
Mexico
Sectors
Healthcare
Government
Technology
Retail
Manufacturing
-
REC
Recon
No techniques detected
-
RD
Resource Dev
No techniques detected
2
IA
Initial Access
T1190 - Exploit Public-Facing Application
T1566 - Phishing
2
EX
Execution
T1059 - Command and Scripting Interpreter
T1203 - Exploitation for Client Execution
1
PE
Persistence
T1505.003 - Web Shell
2
PE
Priv Esc
T1068 - Exploitation for Privilege Escalation
T1055 - Process Injection
-
DE
Defense Evasion
No techniques detected
1
CA
Cred Access
T1003 - OS Credential Dumping
-
DI
Discovery
No techniques detected
1
LM
Lateral Mov
T1021 - Remote Services
-
CO
Collection
No techniques detected
1
C2
C2
T1071 - Application Layer Protocol
2
EX
Exfil
T1041 - Exfiltration Over C2 Channel
T1567 - Exfiltration Over Web Service
-
IM
Impact
No techniques detected
12
techniques detected across
8
tactics
Related Clusters (50)
Critical Zero-Day Vulnerability in Cisco ISE Under Active Exploitation
Sep 16
·
58 sources
89
Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
Aug 12
·
21 sources
81
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure
Sep 11
·
58 sources
81
Critical RCE Vulnerability in Apache Roller 6.1.5 Disclosed
2d ago
·
2 sources
78
Critical PHP Object Injection Vulnerability in WS Form LITE Plugin
Aug 24
·
1 sources
78
Critical RCE Vulnerability in Oracle PeopleSoft Exploited by SHADOW-AETHER-015
Jun 18
·
5 sources
78
Critical RCE Vulnerability in PTC Windchill and FlexPLM Under Active Exploitation
Jun 29
·
2 sources
78
Sandworm Targets Critical Infrastructure with Aggressive OT Attacks
May 14
·
3 sources
77
Critical RCE Vulnerability in Jenkins Exploited in the Wild
Jun 17
·
2 sources
76
Critical OVERPASS Vulnerability in SAP Kernel Requires Immediate Action
Sep 8
·
15 sources
76
Critical Vulnerabilities in pgAdmin 4 Expose Databases to Remote Code Execution
Jun 22
·
6 sources
74
Multiple CVEs Disclosed on September 8, 2026, Affecting Microsoft Products
Sep 8
·
927 sources
74
July 2026 Security Update: Record CVEs and Critical Vulnerabilities
Jul 14
·
2 sources
74
Microsoft's Record Patch Tuesday in June 2026 Addresses 206 Vulnerabilities
Jul 1
·
132 sources
74
Critical Exploitation of Ruby on Rails Vulnerability CVE-2026-66066 Confirmed
Aug 31
·
3 sources
73
Active Exploitation of Microsoft SharePoint Flaw CVE-2026-45659 Confirmed
Jul 4
·
2 sources
73
Critical PHP Object Injection Vulnerability in Mirasvit Cache Warmer
Jun 4
·
4 sources
73
Critical Deserialization Vulnerability in Fedora 44 and 45 perl-Dancer2
2d ago
·
2 sources
73
Critical Vulnerabilities in Kaltura HTML5 Player Expose Organizations to Attacks
Aug 26
·
2 sources
73
Critical Use After Free Vulnerabilities in Fedora Chromium Update
Jun 14
·
2 sources
73
Microsoft Issues Critical Security Patches for August 2026
Aug 12
·
2 sources
73
Ransomware Exploits Critical SharePoint Vulnerability CVE-2026-45659
Aug 11
·
4 sources
73
Critical Remote Code Execution Vulnerability in c3p0 Affects Multiple Ubuntu Versions
Aug 18
·
2 sources
73
Critical RCE Vulnerability in Craft CMS Exploited
3d ago
·
2 sources
73
Critical Vulnerabilities in LangGraph AI Framework Enable Full Server Control
Jun 15
·
5 sources
73
Critical .NET Deserialization Vulnerability in ibaPDA and ibaDatCoordinator
Jun 17
·
2 sources
73
Critical SharePoint RCE Vulnerabilities Exploited in the Wild
Sep 20
·
11 sources
73
Critical RCE Vulnerability in WS_FTP Server Disclosed
Jun 17
·
1 sources
73
Emerging Threats from CVE-2022-26809 and CVE-2023-34362 Exploits
3d ago
·
2 sources
73
Multiple High Severity Vulnerabilities Discovered in SurrealDB
Jul 18
·
3 sources
73
NVIDIA NeMo Framework Vulnerable to High-Severity Command Injection Flaws
Jun 17
·
2 sources
73
Critical RCE Vulnerability in ComfyUI v0.23.0 (CVE-2026-68771)
Aug 2
·
1 sources
72
Critical RCE Vulnerability in Hugging Face Transformers Library Disclosed
Jun 4
·
6 sources
72
Fedora NextCloud Update Addresses JSON Tampering and DoS Vulnerabilities
Jun 5
·
2 sources
72
Critical CVE-2026-76658 Vulnerability in HPE Fabric Composer
Sep 2
·
2 sources
72
Critical Vulnerabilities in Apache Fory Affecting Multiple Versions
May 22
·
1 sources
72
Critical Vulnerabilities Discovered in PickleScan Security Scanner
Jun 18
·
0 sources
72
Over 100,000 WordPress Sites Vulnerable to Remote Code Execution
Sep 17
·
2 sources
72
ILIAS PHP Object Injection Vulnerability Enables Unauthenticated RCE
Sep 14
·
1 sources
72
Critical Path Traversal Vulnerabilities in Fedora Composer 2026
Jul 11
·
2 sources
72
Critical RCE Vulnerabilities Disclosed in NLTK Toolkit
Aug 26
·
1 sources
72
Critical Vulnerabilities in Gogs and Jinjava Require Immediate Patching
Jun 25
·
2 sources
72
Critical RCE Vulnerability in GiveWP Plugin Exposed
Aug 28
·
6 sources
71
Seagull Software BarTender Vulnerabilities Enable RCE and Privilege Escalation
Jun 4
·
1 sources
71
Remote Code Execution Vulnerabilities Found in OpenCode and OpenMed
6d ago
·
2 sources
71
Remote Code Execution Vulnerability in Cal.com Exploited
Sep 8
·
2 sources
71
Cisco Secure Firewall Management Center RCE Vulnerability Disclosed
Sep 16
·
2 sources
71
Remote Code Execution Vulnerability in Splunk Secure Gateway
Jun 11
·
2 sources
71
Critical CVE-2026-69836 in Microsoft Entra ID Exploited in the Wild
Aug 21
·
30 sources
70
Anthropic's Claude Mythos Preview Sparks Cybersecurity Revolution
Apr 7
·
1106 sources
70
Prev
1 / 10
Next
Related Articles (50)
CVE 2026 13046
psirt.watchguard.com
·
20h ago
Hugging Face Transformers Rce Flaw Enables Stealthy Compromise Via Ai Model Configs
www.csoonline.com
·
1d ago
ZDI-26-749: WatchGuard FireWare OS samld SAMLSession Deserialization of Untrusted Data Remote Code Execution Vulnerability
Zerodayinitiative
·
1d ago
Fedora 44 perl-Dancer2 Major Deserialization Vulnerability 2026
Linuxsecurity
·
2d ago
Fedora 45 perl-Dancer2 Critical Deserialization Exploit 2026
Linuxsecurity
·
2d ago
CVE-2026-82384
Mondoo
·
2d ago
Rapid7 Vulnerability & Exploit Database
Rapid7
·
2d ago
Exploit for CVE-2026
Sploitus
·
3d ago
One Email Closer Edge Unkmasstraction Physics Exploitation
www.proofpoint.com
·
3d ago
AI Remote Code Execution: Risks & Solutions
Sweet.Security
·
3d ago
CVE-2023
Sploitus
·
3d ago
Monai Before 1.6.0 Remote Code Execution Via Algo From Pickle
www.vulncheck.com
·
3d ago
GHSA Wg9g W2j2 8pgr
github.com
·
3d ago
Monai Before 1.5.2 Remote Code Execution Via Pickle Deserialization
www.vulncheck.com
·
3d ago
GHSA 89gg P5r5 Q6r4
github.com
·
3d ago
CVE Alert: CVE-2026-100846 – Project-MONAI
Redpacketsecurity
·
4d ago
CVE Alert: CVE-2026-100845 – Project-MONAI
Redpacketsecurity
·
4d ago
CVE Alert: CVE-2026-100843 – Project-MONAI
Redpacketsecurity
·
4d ago
Exploit for Improper Neutralization of Special Elements Used in a Template Engine in Craftcms Craft_Cms
Sploitus
·
4d ago
The August 2026 Security Update Review
www.zerodayinitiative.com
·
5d ago
Your Vulnerability Backlog Is an Attack Surface
Snyk
·
Sep 24
Your Vulnerability Backlog Is an Attack Surface
Snyk
·
Sep 24
CVE Alert: CVE-2026-18490 – IBM – Financial Transaction Manager (FTM) for RedHat OpenShift
Redpacketsecurity
·
Sep 23
CVE Alert: CVE-2026-17637 – IBM – Financial Transaction Manager (FTM) for RedHat OpenShift
Redpacketsecurity
·
Sep 23
HR Software Not Updated for Three Months: How the FBI Just Got Hacked
Emeraldbook
·
Sep 23
AI
Sdtimes
·
Sep 22
CVE-2021
Sploitus
·
Sep 22
CVSS v3.1 score of 9.8
www.tenable.com
·
Sep 20
The Patch Is Not Enough: SharePoint's ToolShell Chain Steals Keys That Outlive the Fix
Forkast.News
·
Sep 20
CVE-2026-45659: SharePoint Deserialization Flaw Enables RCE
Socprime
·
Sep 18
3e29501c33f6e1e05ac2a00107afd64e
gist.github.com
·
Sep 18
CVE Alert: CVE-2026-76834 – b2evolution
Redpacketsecurity
·
Sep 18
100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object ...
Wordfence
·
Sep 17
Bounty Dynamics
www.microsoft.com
·
Sep 17
Squashing vulnerabilities: Microsoft udpates Dynamics 365 bug bounty program
Msdynamicsworld
·
Sep 17
Cisco Secure Firewall Management Center Software Java Deserialization Remote Code ...
Sec.Cloudapps.Cisco
·
Sep 16
Cisco Security Advisory: Cisco Identity Services Engine Remote Code Execution Vulnerabilities
Sec.Cloudapps.Cisco
·
Sep 16
CVE-2026
Sploitus
·
Sep 16
Cisco Identity Services Engine Remote Code Execution Vulnerabilities
Sec.Cloudapps.Cisco
·
Sep 16
IBM MQ Java messaging is vulnerable to remote code execution (CVE-2026-13293)
Ibm
·
Sep 15
GitHub Issue #1563
github.com
·
Sep 14
LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Config Server Pickle ...
Vulncheck
·
Sep 14
Falla crítica en plugin educativo de WordPress permite ejecución remota de código con cuenta básica
Ciberseguridadlatam
·
Sep 14
Source: Exploit DB
www.exploit-db.com
·
Sep 14
CVE-2016
Sploitus
·
Sep 13
Fedora 44 mongo-c-driver Update Security Advisory FEDORA-2026
Linuxsecurity
·
Sep 13
ILIAS Unauthenticated PHP Object Injection Leads to RCE
Redsecuretech
·
Sep 13
The Events Calendar Remote Code Execution
Wordfence
·
Sep 12
GitLab Issues Emergency Security Update For Maximum-Severity Vulnerability
Linkedin
·
Sep 12
[vulnfeed] 10 critical CVEs — 2026-09-11 20:00 UTC
Buttondown
·
Sep 12
Prev
1 / 10
Next
Related Entities
ShinyHunters
Shadow-aether-015
Zero-day Exploit
Data Breach
Malware
Remote Code Execution
Sql Injection
Ransomware
Phishing
Supply Chain Attack
DDoS
Denial of Service