CVE-2026-50515
Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.
CVSS
9.9
Crítico
EPSS
—
KEV
—
Exploit Today
0
0-100
Publicado: 7 ago 2026 · Última mod.: 7 ago 2026 · CWE-502
Sin historial EPSS suficiente todavía.
Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-71560——
——0Out-of-bounds Read vulnerability in Apache Fory C++ deserialization.
This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deserializing structs containing tagged integer fields. A crafted input payload may trigger an out-of-bounds heap read in the tagged integer fast-path deserializer, potentially causing information disclosure or denial of service.
Users are recommended to upgrade to Apache Fory 1.5.0, which fixes this issue. Applications that do not use Apache Fory C++ or do not use tagged integer fields are not affected.6hCVE-2026-71559——
——0Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic.
This issue affects Apache Fory: from 0.16.0 before 1.5.0. Users of other language implementations are not affected.
Users are recommended to upgrade to version 1.5.0, which fixes the issue.6hCVE-2026-71558——
——0Heap type confusion vulnerability in Apache Fory C++ deserialization.
This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic smart-pointer deserialization, causing an object of an incompatible type to be treated as the declared base type. This may result in undefined behavior and potentially lead to denial of service or arbitrary code execution.
Users are recommended to upgrade to Apache Fory 1.5.0, which fixes this issue. Applications not using Apache Fory C++ polymorphic smart-pointer deserialization are not affected.6hCVE-2026-655819.8 CRÍ—
——0Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.18hCVE-2026-655799.8 CRÍ—
——0Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions.1dCVE-2026-655789.8 CRÍ—
——0Unauthenticated PHP Object Injection in Agora <= 1.9 versions.18h