deserialization
Safeguard articles tagged "deserialization" — guides, analysis, and best practices for software supply chain and application security.
70 articles
Your Config Parser Is an Interpreter and the File Chooses What It Does
Configuration feels inert because it looks like data. Several formats can execute code and several loaders will by default, which makes parsing a security decision the moment the file comes from anywhere but your own repository.
Roundcube's Same-Day KEV Entries: A 9.9 Deserialization Bug and an SVG XSS Foothold
A near-maximum-severity PHP deserialization RCE and a stored XSS bug via SVG animate tags landed in CISA's KEV catalogue on the same date, describing a realistic foothold-to-RCE chain.
A Joomla Editor and a Magento Cache Warmer Both Delivered Unauthenticated RCE at 9.8
Widget Factory's JCE editor and Mirasvit's Full Page Cache Warmer reached identical maximum severity through completely different root causes — a missing permission check and a PHP deserialization flaw.
SolarWinds Web Help Desk's Deserialization Problem, Confirmed for Ransomware
Two separate deserialization RCEs and a security-control bypass in Web Help Desk, one confirmed for ransomware use, plus a denial-of-service bug in Serv-U.
SharePoint and Exchange Produce Four More Confirmed-Exploited CVEs
Beyond the five-CVE cluster covered earlier, four more SharePoint and Exchange vulnerabilities were confirmed exploited across the year — including a 2023 Exchange bug confirmed nearly three years later.
WSUS and Configuration Manager: When Patch Infrastructure Itself Needs Patching
CVE-2025-59287 in WSUS and CVE-2024-43468 in Configuration Manager both scored CVSS 9.8 — critical bugs in the very tools organizations use to distribute trust across their fleet.
PTC Windchill and FlexPLM's Deserialization RCE Is Confirmed Tied to Ransomware
CVE-2026-12569, a deserialization RCE in PTC's product lifecycle management platforms, carries CISA's confirmed ransomware campaign flag — a notable finding in specialised industrial software.
Five SharePoint CVEs in Five Weeks: The Deserialization Habit Continues
Microsoft SharePoint had five vulnerabilities confirmed exploited between July and August 2026, three of them the same root cause: deserialization of untrusted data. One carries CISA's confirmed ransomware flag.
CVE-2026-63077: Your Build Server Is a Credential Store With an Open Port
An unauthenticated attacker sends a crafted object to TeamCity's agent polling endpoint and gets OS command execution as the server process. Every credential the build server holds sits downstream.
CVE-2023-22102: The MySQL Connector/J Takeover Vulnerability
CVE-2023-22102 is a High-severity flaw in Oracle's MySQL Connector/J that can lead to connector takeover. Here is the root cause and how to remediate it.
Jenkins CLI Deserialization RCE via Commons-Collections G...
CVE-2015-8103: unauthenticated RCE in Jenkins CLI via a Commons-Collections deserialization gadget chain. Impact, timeline, and remediation.
LangGraph CVE-2025-64439: When Agent Checkpoints Become RCE
A JsonPlusSerializer fallback in langgraph-checkpoint let attacker-controlled payloads execute arbitrary Python on deserialization. We unpack the bug, the patch, and what agent operators must change.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.