CISA Warns of Active JetBrains TeamCity Flaw
A deserialization vulnerability in JetBrains TeamCity is under active exploitation, forcing federal agencies to patch systems by August 8, 2026.
9 results for “deserialization”
A deserialization vulnerability in JetBrains TeamCity is under active exploitation, forcing federal agencies to patch systems by August 8, 2026.
A critical remote code execution vulnerability in Flowise's CSVAgent allows attackers to bypass python code filters using pandas read_pickle deserialization.
An unauthenticated remote code execution vulnerability in Kotaemon allows attackers to run arbitrary system commands by exploiting insecure deserialization.
A critical deserialization vulnerability in ComfyUI allows unauthenticated attackers to execute arbitrary code on affected systems.
A critical deserialization vulnerability in IBM webMethods Integration allows unauthenticated remote attackers to execute arbitrary code on affected systems.
A deserialization vulnerability in OpenAM's WebAuthn module allows remote code execution through an object filter depth bypass.
A type confusion vulnerability in seroval.fromJSON() allows attackers to trigger unintended server-side code execution through malicious JSON payloads.
A critical deserialization vulnerability in Microsoft SharePoint is currently being exploited in the wild, requiring immediate action from federal agencies.
A deserialization vulnerability in Microsoft SharePoint is currently being exploited in the wild, prompting an urgent remediation deadline for federal agencies.