Safeguard
Tag

deserialization

Safeguard articles tagged "deserialization" — guides, analysis, and best practices for software supply chain and application security.

70 articles

Application Security

Your Config Parser Is an Interpreter and the File Chooses What It Does

Configuration feels inert because it looks like data. Several formats can execute code and several loaders will by default, which makes parsing a security decision the moment the file comes from anywhere but your own repository.

Sep 18, 20265 min read
Vulnerability Analysis

Roundcube's Same-Day KEV Entries: A 9.9 Deserialization Bug and an SVG XSS Foothold

A near-maximum-severity PHP deserialization RCE and a stored XSS bug via SVG animate tags landed in CISA's KEV catalogue on the same date, describing a realistic foothold-to-RCE chain.

Sep 16, 20265 min read
Vulnerability Analysis

A Joomla Editor and a Magento Cache Warmer Both Delivered Unauthenticated RCE at 9.8

Widget Factory's JCE editor and Mirasvit's Full Page Cache Warmer reached identical maximum severity through completely different root causes — a missing permission check and a PHP deserialization flaw.

Sep 16, 20265 min read
Vulnerability Analysis

SolarWinds Web Help Desk's Deserialization Problem, Confirmed for Ransomware

Two separate deserialization RCEs and a security-control bypass in Web Help Desk, one confirmed for ransomware use, plus a denial-of-service bug in Serv-U.

Sep 16, 20264 min read
Vulnerability Analysis

SharePoint and Exchange Produce Four More Confirmed-Exploited CVEs

Beyond the five-CVE cluster covered earlier, four more SharePoint and Exchange vulnerabilities were confirmed exploited across the year — including a 2023 Exchange bug confirmed nearly three years later.

Sep 16, 20264 min read
Vulnerability Analysis

WSUS and Configuration Manager: When Patch Infrastructure Itself Needs Patching

CVE-2025-59287 in WSUS and CVE-2024-43468 in Configuration Manager both scored CVSS 9.8 — critical bugs in the very tools organizations use to distribute trust across their fleet.

Sep 16, 20264 min read
Vulnerability Analysis

PTC Windchill and FlexPLM's Deserialization RCE Is Confirmed Tied to Ransomware

CVE-2026-12569, a deserialization RCE in PTC's product lifecycle management platforms, carries CISA's confirmed ransomware campaign flag — a notable finding in specialised industrial software.

Sep 16, 20264 min read
Vulnerability Analysis

Five SharePoint CVEs in Five Weeks: The Deserialization Habit Continues

Microsoft SharePoint had five vulnerabilities confirmed exploited between July and August 2026, three of them the same root cause: deserialization of untrusted data. One carries CISA's confirmed ransomware flag.

Sep 16, 20264 min read
Vulnerability Analysis

CVE-2026-63077: Your Build Server Is a Credential Store With an Open Port

An unauthenticated attacker sends a crafted object to TeamCity's agent polling endpoint and gets OS command execution as the server process. Every credential the build server holds sits downstream.

Aug 11, 20267 min read
Security

CVE-2023-22102: The MySQL Connector/J Takeover Vulnerability

CVE-2023-22102 is a High-severity flaw in Oracle's MySQL Connector/J that can lead to connector takeover. Here is the root cause and how to remediate it.

Aug 1, 20265 min read
DevSecOps

Jenkins CLI Deserialization RCE via Commons-Collections G...

CVE-2015-8103: unauthenticated RCE in Jenkins CLI via a Commons-Collections deserialization gadget chain. Impact, timeline, and remediation.

Jul 25, 20269 min read
Agent Security

LangGraph CVE-2025-64439: When Agent Checkpoints Become RCE

A JsonPlusSerializer fallback in langgraph-checkpoint let attacker-controlled payloads execute arbitrary Python on deserialization. We unpack the bug, the patch, and what agent operators must change.

Jul 23, 20266 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.