NLTK Mass Disclosure — 4 CVEs, Peak 9.8 (Allowlisted Pickle RCE) ThreatAft — Cybersecurity Intelligence / 12h A mass disclosure of four CVEs across versions before 3.10.3 just dropped, with CVE-2026-79657 leading at CVSS 9.8 — an unsafe pickle deserialization vulnerability where allowlisted pickle loaders trust entire module namespaces, allowing arbitrary code execution via crafted model files. CVSS 9.8 — Critical pickle deserialization RCE — CVE-2026-79657 allows attackers to execute arbitrary