Insecure Deserialization - Vulnerability

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
December 15, 2025
Last Seen
June 2, 2026

Insecure Deserialization is a vulnerability tracked across 4 threat clusters and 4 intelligence report mentions on ThreatCluster. First observed December 15, 2025; most recent activity June 2, 2026.

Overview

Insecure deserialization is a vulnerability where untrusted serialized data is deserialized by an application, allowing attackers to craft payloads that can execute arbitrary code, cause crashes, or trigger denial-of-service conditions. It is a high-risk issue across services and pipelines that reconstruct objects from serialized input, including web apps, APIs, and ML inference workflows. Its significance lies in the potential for remote code execution and disruption of availability in diverse software ecosystems.

Related Threat Clusters

  • SAP Patch Day Addresses Critical Vulnerabilities

    On March 10, 2026, SAP released 15 security notes, including two critical vulnerabilities that could allow remote code execution and system compromise. Administrators are urged to apply the patches promptly to protect…

    10 articles · Updated March 10, 2026
  • Remote Code Execution Vulnerabilities in Apache ActiveMQ and OFBiz Detected

    On June 1 and 2, 2026, Snort published alerts for remote code execution attempts targeting Apache ActiveMQ and Apache OFBiz. The ActiveMQ vulnerability involves insecure deserialization, allowing attackers to execute…

    6 articles · Updated June 2, 2026
  • NVIDIA Merlin Vulnerabilities Enable Code Execution and DoS Attacks

    NVIDIA has released security patches for its Merlin machine learning framework due to two high-severity deserialization vulnerabilities. These vulnerabilities, identified as CVE-2025-33214 and CVE-2025-33213, could…

    3 articles · Updated December 15, 2025
  • AI Agents Excel in Web Security CTF Challenges

    In a study conducted by Irregular in collaboration with Wiz, AI agents successfully solved nine out of ten web security capture-the-flag (CTF) challenges. The challenges were based on real-world vulnerabilities,…

    2 articles · Updated January 30, 2026

Recent Intelligence Reports

  • Rule Docs 1:66532 — Snort · June 2, 2026
  • SAP Releases Patches for Security Flaws Allowing Remote Code Execution — Linkedin · March 10, 2026
  • AI Agents vs Humans: Who Wins at Web Hacking in 2026? — Wiz · January 29, 2026
  • NVIDIA Merlin Vulnerabilities Let Attackers Execute Malicious Code and Trigger DoS Condition — Cybersecuritynews · December 15, 2025

CVSS v3.1 Breakdown