CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Unsafe deserialization vulnerabilities

insecure deserialization83 advisories55 exploitedlatest 2026-08-25

Unsafe deserialization occurs when untrusted data is deserialized into live objects — in Java, .NET, PHP or Python — letting attackers instantiate gadget chains that end in code execution. Almost every advisory in this class is effectively an RCE, which its exploitation rate reflects.

Classification is assigned by the CSIRTS enrichment pipeline from the advisory text. The list below shows the latest advisories tagged unsafe deserialization, newest first, across national CERTs, vendor PSIRTs and vulnerability databases — exploited marks CVEs in the CISA KEV catalog.

Latest unsafe deserialization advisories

Other vulnerability classes

Remote code execution (2023)Privilege escalation (1548)Authentication bypass (1066)Denial of service (2105)Information disclosure (1543)Memory corruption (1308)Path traversal (235)Code injection (343)Cross-site scripting (315)SQL injection (143)Server-side request forgery (109)
New unsafe deserialization advisories, in your inbox. The daily briefing covers every advisory in this class the morning after it lands. Subscribe free — one email every morning after 06:00 UTC, one-click unsubscribe. Tracking specific products instead? Watch them from any product page and get alerted only when they ship a new advisory.