CVE-2026-24237
NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of
CVSS
7.8
High
EPSS
0.2%
p7
KEV
—
Exploit Today
2
0-100
Published: Jun 2, 2026 · Last modified: Jul 22, 2026 · CWE-502
0.2%EPSS · 30 days0.2%
2026-07-052026-08-02
NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-186427.8 HIG—
———Deserialization of untrusted data vulnerability in TUBITAK BILGEM Software Technologies Research Institute eta-otp-lock allows Object Injection.
This issue affects eta-otp-lock: before 1.0.4.5hCVE-2026-162974.1 MED—
——0The Clearfy Cache WordPress plugin before 2.4.3 does not restrict the classes allowed when unserializing settings-import data, allowing users with administrator access to perform PHP Object Injection attacks, which may lead to remote code execution when a suitable gadget chain is present in the environment.2hCVE-2026-32457.5 HIG—
——0A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.3hCVE-2026-687719.8 CRI46.5%
——14ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserialization. Attackers can upload a malicious shard_*.pkl file via the unauthenticated POST /upload/image endpoint and then queue a workflow graph via POST /prompt referencing the uploaded file, causing torch.load to deserialize the attacker-controlled pickle payload using __reduce__ and execute arbitrary commands as the ComfyUI process user.3dCVE-2026-127207.5 HIG22.8%
——7The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated users can store, leading to PHP Object Injection that is triggered when an administrator later reviews the stored data. With a suitable gadget chain present on the site (via another installed Kirki WordPress plugin before 6.0.13, , or an outdated WordPress version), this could be leveraged to perform a variety of attacks, such as remote code execution.3dCVE-2026-115368.5 HIG26.3%
——8IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector.4d