PoC Archive PoC Archive

tag

Deserialization

TeamCity — Unauthenticated RCE via Agent Polling Deserialization (CVE-2026-63077) KEV EPSS 88%
CVE-2026-63077 web Patched
CVE-2026-63077webCRITICAL 9.8Patched2026-08-09Alibaba Fastjson 1.x checkAutoType Bypass to Remote Code Execution via jar:http SSRF and fd-Reread Trick (CVE-2026-16723) EPSS 16%
CVE-2026-16723 web Unpatched
CVE-2026-16723webCRITICAL 9Unpatched2026-07-31Microsoft SharePoint Server WS-Federation SecurityContextToken Deserialization → Unauthenticated RCE (CVE-2026-50522) KEV EPSS 85%
CVE-2026-50522 web Patched
CVE-2026-50522webCRITICAL 9.8Patched2026-07-27GitLab Notebook-Diff Oj Parser Memory-Corruption Chain → Unauthenticated-Reach RCE (No CVE Yet)
N/A (no CVE assigned as of 2026-07-27 — researcher disclosure via depthfirst.com blog, covered by The Hacker News) web Unverified
N/AwebCRITICALUnverified2026-07-27Sitecore XP Report.ashx Insecure Deserialization RCE (CVE-2021-42237) KEV RW EPSS 98%
CVE-2021-42237 (Sitecore advisory SC2021-003-499266) web Patched
CVE-2021-42237webCRITICAL 9.8Patched2026-07-11Roundcube Webmail Post-Auth RCE via PHP Object Deserialization (CVE-2025-49113) KEV EPSS 99%
CVE-2025-49113 web Patched
CVE-2025-49113webCRITICAL 9.9Patched2026-07-06React Server Components Flight-Protocol Prototype Pollution RCE — "React2Shell" (CVE-2025-55182) KEV RW EPSS 100%
CVE-2025-55182 web Patched
CVE-2025-55182webCRITICAL 10Patched2026-07-06Laravel Livewire Remote Code Execution via Known APP_KEY (CVE-2025-54068) KEV EPSS 96%
CVE-2025-54068 web Patched
CVE-2025-54068webCRITICAL 9.8Patched2026-07-06GiveWP Unauthenticated PHP Object Injection via Weak Serialized-Data Regex Check (CVE-2025-22777)
CVE-2025-22777 web Patched
CVE-2025-22777webCRITICAL 9.8Patched2026-07-06WP Zendesk for Contact Form 7 Unauthenticated PHP Object Injection (CVE-2026-49105)
CVE-2026-49105 web Unverified
CVE-2026-49105webHIGH 8.1Unverified2026-07-05WP Insightly Contact Form Plugin Unauthenticated PHP Object Injection (CVE-2026-49085)
CVE-2026-49085 web Unverified
CVE-2026-49085webHIGH 8.1Unverified2026-07-05WP Activity Log Unauthenticated PHP Object Injection — CVE-2026-54806
CVE-2026-54806 web Patched
CVE-2026-54806webCRITICAL 9.8Patched2026-07-05Splunk Secure Gateway jsonpickle Deserialization RCE (CVE-2026-20251) EPSS 32%
CVE-2026-20251 web Unverified
CVE-2026-20251webHIGH 8.8Unverified2026-07-05SP LMS PHP Object Injection → Unauthenticated RCE (CVE-2026-48909)
CVE-2026-48909 (GHSA-gf8c-xmwj-whrh) web Patched
CVE-2026-48909webCRITICAL 9.5Patched2026-07-05OpenAM Pre-Authentication RCE via `jato.clientSession` Deserialization (CVE-2026-33439) EPSS 10%
CVE-2026-33439 web Patched
CVE-2026-33439webCRITICAL 9.8Patched2026-07-05Node.js protobufjs Dynamic Type Compilation RCE (CVE-2026-41242)
CVE-2026-41242 web Patched
CVE-2026-41242webCRITICALPatched2026-07-05KnowledgeDeliver ASP.NET ViewState Deserialization RCE via Hardcoded Machine Keys — CVE-2026-5426
CVE-2026-5426 web Unverified
CVE-2026-5426webCRITICALUnverified2026-07-05Jinjava Server-Side Template Injection to RCE via Jackson ObjectMapper (CVE-2026-25526)
CVE-2026-25526 web Patched
CVE-2026-25526webCRITICALPatched2026-07-05Jenkins ClassFilter Deserialization Bypass → Arbitrary File Read — CVE-2026-53435 EPSS 53%
CVE-2026-53435 (Jenkins SECURITY-3707) web Patched
CVE-2026-53435webHIGH 9.1Patched2026-07-05Integration for Keap/Infusionsoft Contact Form Plugin Unauthenticated PHP Object Injection (CVE-2026-49104)
CVE-2026-49104 web Unverified
CVE-2026-49104webHIGH 8.1Unverified2026-07-05Integration for ActiveCampaign Unauthenticated PHP Object Injection via Unsafe Deserialization (CVE-2026-9691)
CVE-2026-9691 web Unpatched
CVE-2026-9691webHIGH 8.1Unpatched2026-07-05Group-Office PHP Deserialization Remote Code Execution (CVE-2026-34838)
CVE-2026-34838 (GHSA-h22j-frrf-5vxq) web Patched
CVE-2026-34838webCRITICALPatched2026-07-05Feast Registry gRPC Unauthenticated RCE via dill.loads — CVE-2026-56121
CVE-2026-56121 misc Patched
CVE-2026-56121miscCRITICAL 9.8Patched2026-07-05Everest Forms Unauthenticated PHP Object Injection to RCE (CVE-2026-3296)
CVE-2026-3296 web Patched
CVE-2026-3296webCRITICAL 9.8Patched2026-07-05Apache Tomcat Tribes EncryptInterceptor Fail-Open Unauthenticated RCE (CVE-2026-34486) KEV EPSS 99%
CVE-2026-34486 web Patched
CVE-2026-34486webCRITICALPatched2026-07-05Apache MINA acceptMatchers Deserialization Filter Bypass to RCE (CVE-2026-42779)
CVE-2026-42779 network Patched
CVE-2026-42779networkCRITICAL 9.8Patched2026-07-05Redis Vector Set Duplicate HNSW Node ID RCE
None assigned as of 2026-07-03 network Unverified
None assigned as of 2026-07-03networkCRITICALUnverified2026-07-03ToolShell - SharePoint Unauthenticated RCE Chain KEV RW EPSS 100%
CVE-2025-53770, CVE-2025-53771, CVE-2025-49704, CVE-2025-49706 web Patched
CVE-2025-53770, CVE-2025-53771, CVE-2025-49704, CVE-2025-49706webCRITICALPatched2026-05-17React2Shell - Next.js RSC Unauthenticated RCE KEV RW EPSS 100%
CVE-2025-55182 web Patched
CVE-2025-55182webCRITICAL 10Patched2026-05-17Next.js RSC Server-Action DoS via Flight Deserialization (CVE-2026-23870)
CVE-2026-23870 web Patched
CVE-2026-23870webHIGH 7.5Patched2026-05-17Confluence Post-Auth RCE - CVE-2024-21683 EPSS 88%
CVE-2024-21683 web Unverified
CVE-2024-21683webHIGH 8.3Unverified2026-05-17