CVE-2026-3245
A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.
CVSS
7.5
High
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Aug 3, 2026 · Last modified: Aug 3, 2026 · CWE-502
Not enough EPSS history yet.
A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.
- cpp.canonhttps://cpp.canon/vulnerability-in-prismaproduction-cve-2026-3245/
- psirt.canonhttps://psirt.canon/advisory-information/cp2026-007/
- www.canon-europe.comhttps://www.canon-europe.com/support/product-security/
- www.usa.canon.comhttps://www.usa.canon.com/about-us/to-our-customers/cpa2026-007-vulnerability-in-prismaproduction
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-687719.8 CRI46.5%
——14ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserialization. Attackers can upload a malicious shard_*.pkl file via the unauthenticated POST /upload/image endpoint and then queue a workflow graph via POST /prompt referencing the uploaded file, causing torch.load to deserialize the attacker-controlled pickle payload using __reduce__ and execute arbitrary commands as the ComfyUI process user.2dCVE-2026-127207.5 HIG22.8%
——7The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated users can store, leading to PHP Object Injection that is triggered when an administrator later reviews the stored data. With a suitable gadget chain present on the site (via another installed Kirki WordPress plugin before 6.0.13, , or an outdated WordPress version), this could be leveraged to perform a variety of attacks, such as remote code execution.3dCVE-2026-115368.5 HIG26.3%
——8IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector.3dCVE-2026-159769.8 CRI25.8%
——8SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically within the /update_weights_from_disk, where torch.load(..., weights_only=False) fallback enables pickle deserialization of .bin files.3dCVE-2026-159699.8 CRI58.8%
——18SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitrary command execution through crafted base64-encoded pickle payloads.3dCVE-2026-121189.8 CRI40.0%
——12IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data.4d