Insecure Deserialization is a vulnerability tracked across 4 threat clusters and 4 intelligence report mentions on ThreatCluster. First observed December 15, 2025; most recent activity June 2, 2026.
Insecure deserialization is a vulnerability where untrusted serialized data is deserialized by an application, allowing attackers to craft payloads that can execute arbitrary code, cause crashes, or trigger denial-of-service conditions. It is a high-risk issue across services and pipelines that reconstruct objects from serialized input, including web apps, APIs, and ML inference workflows. Its significance lies in the potential for remote code execution and disruption of availability in diverse software ecosystems.
On March 10, 2026, SAP released 15 security notes, including two critical vulnerabilities that could allow remote code execution and system compromise. Administrators are urged to apply the patches promptly to protect…
On June 1 and 2, 2026, Snort published alerts for remote code execution attempts targeting Apache ActiveMQ and Apache OFBiz. The ActiveMQ vulnerability involves insecure deserialization, allowing attackers to execute…
NVIDIA has released security patches for its Merlin machine learning framework due to two high-severity deserialization vulnerabilities. These vulnerabilities, identified as CVE-2025-33214 and CVE-2025-33213, could…
In a study conducted by Irregular in collaboration with Wiz, AI agents successfully solved nine out of ten web security capture-the-flag (CTF) challenges. The challenges were based on real-world vulnerabilities,…