CVE-2026-18634
An insecure handling of serialized objects vulnerability was found in the one of the service of GMS application 9.5.1 (Build 9510.1044) and
CVSS
—
Sin CVSS
EPSS
—
KEV
—
Exploit Today
0
0-100
Publicado: 11 ago 2026 · Última mod.: 12 ago 2026 · CWE-502
Sin historial EPSS suficiente todavía.
An insecure handling of serialized objects vulnerability was found in the one of the service of GMS application 9.5.1 (Build 9510.1044) and earlier versions. A local attacker with the ability to interact with the service could exploit this behavior to perform unauthorized actions through the affected component.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-483978.6 ALT—
——0Lightroom Classic is affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.9hCVE-2026-703218.8 ALT—
——0Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.9hCVE-2026-668088.8 ALT—
——0Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.9hCVE-2026-668058.8 ALT—
——0Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.9hCVE-2026-658158.8 ALT—
——0Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.9hCVE-2026-656658.8 ALT—
——0Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.9h