Cwe-502 - Deserialization Of Untrusted Data - Cwe

Threat entity extracted from intelligence sources

Frequency
84
occurrences
First Seen
April 14, 2026
Last Seen
July 24, 2026

Cwe-502 - Deserialization Of Untrusted Data is a cwe tracked across 50 threat clusters and 84 intelligence report mentions on ThreatCluster. First observed April 14, 2026; most recent activity July 24, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • CVE-2025-49113 — nvd.nist.gov · July 24, 2026
  • Rust In Peqace — Scadastrangelove.Blogspot · July 23, 2026
  • CVE-2026-16723 CVE Vulnerability Disclosures / 7h A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required. — cve.report · July 23, 2026
  • ta458 roundpress exploits — Proofpoint · July 23, 2026
  • The July 2026 Security Update Review — www.zerodayinitiative.com · July 22, 2026
  • Three Zero Days 570 Flaws Microsoft S July 2026 Patch Tuesday Sets A New Record — www.secpod.com · July 22, 2026
  • CVE-2024-58362 Vulnerability — CVSS 8.8, HIGH Severity — Ismalicious · July 18, 2026
  • AI supply chain attacks — hivesecurity.gitlab.io · July 17, 2026

CVSS v3.1 Breakdown