<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Deserialization</title><description>Cybersecurity articles tagged #Deserialization on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>CVE-2021-23758: Ajax.NET RCE via Deserialization of Untrusted Data</title><link>https://runtimerebel.com/blog/cve-2021-23758-ajax-net-rce-via-deserialization-of-untrusted-data</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2021-23758-ajax-net-rce-via-deserialization-of-untrusted-data</guid><description>CVE-2021-23758 in Ajax.NET Professional allows remote code execution via untrusted data deserialization, with CISA confirming active exploitation.</description><pubDate>Tue, 01 Sep 2026 02:58:41 GMT</pubDate><category>CVE-2021-23758</category><category>Ajax NET Professional</category><category>Deserialization</category><category>Remote Code Execution</category><category>CISA KEV</category></item><item><title>Microsoft Entra ID RCE Flaw CVE-2026-69836 Fully Mitigated</title><link>https://runtimerebel.com/blog/microsoft-entra-id-rce-flaw-cve-2026-69836-fully-mitigated</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-entra-id-rce-flaw-cve-2026-69836-fully-mitigated</guid><description>Microsoft has fully mitigated a critical remote code execution flaw, CVE-2026-69836, in Entra ID (formerly Azure AD). No customer action is required.</description><pubDate>Sun, 23 Aug 2026 08:18:38 GMT</pubDate><category>Microsoft Entra ID</category><category>Azure AD</category><category>Remote Code Execution</category><category>Deserialization</category><category>Cloud Security</category></item><item><title>CVE-2026-63077: JetBrains TeamCity RCE via Deserialization</title><link>https://runtimerebel.com/blog/cve-2026-63077-jetbrains-teamcity-rce-via-deserialization</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-63077-jetbrains-teamcity-rce-via-deserialization</guid><description>CISA adds CVE-2026-63077 to KEV, indicating active exploitation of a JetBrains TeamCity deserialization RCE vulnerability.</description><pubDate>Tue, 11 Aug 2026 16:54:33 GMT</pubDate><category>CVE-2026-63077</category><category>JetBrains TeamCity</category><category>Deserialization</category><category>Remote Code Execution</category><category>CISA KEV</category></item><item><title>CVE-2026-50522: SharePoint RCE via Deserialization — Patch Now</title><link>https://runtimerebel.com/blog/cve-2026-50522-sharepoint-rce-via-deserialization-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-50522-sharepoint-rce-via-deserialization-patch-now</guid><description>CISA confirmed active exploitation of CVE-2026-50522 in Microsoft SharePoint. Attackers leverage a deserialization vulnerability to execute code remotely. Patch…</description><pubDate>Sun, 02 Aug 2026 16:49:14 GMT</pubDate><category>CVE-2026-50522</category><category>Microsoft SharePoint</category><category>Deserialization</category><category>Remote Code Execution</category><category>CISA KEV</category></item><item><title>FastJson Zero-Day RCE Exploitation Targets US Firms</title><link>https://runtimerebel.com/blog/fastjson-zero-day-rce-exploitation-targets-us-firms</link><guid isPermaLink="true">https://runtimerebel.com/blog/fastjson-zero-day-rce-exploitation-targets-us-firms</guid><description>Hackers are actively exploiting a Zero-Day RCE vulnerability in the FastJson Java library, enabling remote code execution against US firms.</description><pubDate>Tue, 28 Jul 2026 02:37:59 GMT</pubDate><category>Fastjson</category><category>RCE</category><category>Zero-Day</category><category>Java</category><category>Us Firms</category><category>Deserialization</category></item><item><title>CVE-2024-45133: Apache Druid RCE via YAML Deserialization</title><link>https://runtimerebel.com/blog/cve-2024-45133-apache-druid-rce-via-yaml-deserialization</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-45133-apache-druid-rce-via-yaml-deserialization</guid><description>Critical unauthenticated RCE in Apache Druid CVE-2024-45133 allows attackers to execute code via unsafe SnakeYAML deserialization in ingestion tasks.</description><pubDate>Thu, 02 Jul 2026 07:41:21 GMT</pubDate><category>Apache Druid</category><category>CVE-2024-45133</category><category>RCE</category><category>Snakeyaml</category><category>Deserialization</category><category>Patch Management</category></item><item><title>CVE-2026-45659: SharePoint RCE Exploitation - Mitigation Guide</title><link>https://runtimerebel.com/blog/cve-2026-45659-sharepoint-rce-exploitation-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-45659-sharepoint-rce-exploitation-mitigation-guide</guid><description>CISA adds CVE-2026-45659, a high-severity SharePoint Server deserialization flaw, to KEV catalog after confirmed active exploitation by threat actors.</description><pubDate>Thu, 02 Jul 2026 07:34:50 GMT</pubDate><category>CVE-2026-45659</category><category>Microsoft SharePoint</category><category>Deserialization</category><category>CISA KEV</category><category>Remote Code Execution</category></item><item><title>CVE-2026-45247: Magento Mirasvit Cache Warmer RCE Exploit Analysis</title><link>https://runtimerebel.com/blog/cve-2026-45247-magento-mirasvit-cache-warmer-rce-exploit-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-45247-magento-mirasvit-cache-warmer-rce-exploit-analysis</guid><description>CISA adds CVE-2026-45247, a critical Mirasvit Cache Warmer RCE flaw impacting Magento sites, to the KEV catalog following reports of active exploitation.</description><pubDate>Thu, 04 Jun 2026 09:25:50 GMT</pubDate><category>CVE-2026-45247</category><category>Magento</category><category>Mirasvit</category><category>RCE</category><category>CISA KEV</category><category>Deserialization</category></item><item><title>CVE-2026-45247: Mirasvit Full Page Cache Warmer Exploited — Patch Now</title><link>https://runtimerebel.com/blog/cve-2026-45247-mirasvit-full-page-cache-warmer-exploited-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-45247-mirasvit-full-page-cache-warmer-exploited-patch-now</guid><description>CISA adds CVE-2026-45247, a deserialization vulnerability in Mirasvit Full Page Cache Warmer for Magento, to the KEV catalog after reports of active exploitation.</description><pubDate>Wed, 03 Jun 2026 17:47:53 GMT</pubDate><category>CVE-2026-45247</category><category>Mirasvit</category><category>Magento</category><category>CISA KEV</category><category>RCE</category><category>Deserialization</category></item><item><title>CVE-2026-45659: SharePoint RCE via Deserialization - Patch Now</title><link>https://runtimerebel.com/blog/cve-2026-45659-sharepoint-rce-via-deserialization-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-45659-sharepoint-rce-via-deserialization-patch-now</guid><description>Microsoft addresses CVE-2026-45659, a high-severity RCE flaw in SharePoint Server caused by untrusted data deserialization. Learn how to mitigate this risk.</description><pubDate>Tue, 26 May 2026 13:10:28 GMT</pubDate><category>CVE-2026-45659</category><category>SharePoint</category><category>RCE</category><category>Microsoft</category><category>Deserialization</category></item><item><title>Hugging Face LeRobot RCE via CVE-2026-25874 — Mitigation Guide</title><link>https://runtimerebel.com/blog/hugging-face-lerobot-rce-via-cve-2026-25874-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/hugging-face-lerobot-rce-via-cve-2026-25874-mitigation-guide</guid><description>Technical analysis of CVE-2026-25874, a critical unpatched RCE vulnerability in Hugging Face LeRobot robotics platform with a CVSS score of 9.3.</description><pubDate>Tue, 28 Apr 2026 12:43:39 GMT</pubDate><category>CVE-2026-25874</category><category>Hugging Face</category><category>LeRobot</category><category>RCE</category><category>Robotics</category><category>Deserialization</category></item><item><title>CISA KEV Update: Exchange Server, Adobe, MS Windows Exploits</title><link>https://runtimerebel.com/blog/cisa-kev-update-exchange-server-adobe-ms-windows-exploits</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-kev-update-exchange-server-adobe-ms-windows-exploits</guid><description>CISA adds seven vulnerabilities, including critical Microsoft Exchange Server deserialization, to its Known Exploited Vulnerabilities Catalog, urging immediate…</description><pubDate>Tue, 14 Apr 2026 00:47:03 GMT</pubDate><category>CVE-2012-1854</category><category>CVE-2020-9715</category><category>CVE-2023-21529</category><category>CVE-2023-36424</category><category>CVE-2025-60710</category><category>CVE-2026-21643</category><category>CVE-2026-34621</category><category>Microsoft Exchange Server</category><category>Adobe Acrobat</category><category>Microsoft Windows</category><category>Fortinet</category><category>CISA</category><category>KEV Catalog</category><category>Deserialization</category><category>Use After Free</category><category>SQL Injection</category></item><item><title>CVE-2026-4681: Critical RCE in PTC Windchill &amp; FlexPLM</title><link>https://runtimerebel.com/blog/cve-2026-4681-critical-rce-in-ptc-windchill-flexplm</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-4681-critical-rce-in-ptc-windchill-flexplm</guid><description>Critical RCE vulnerability CVE-2026-4681 affects PTC Windchill and FlexPLM via deserialization. Patch now to prevent code injection in critical manufacturing.</description><pubDate>Thu, 26 Mar 2026 16:40:04 GMT</pubDate><category>CVE-2026-4681</category><category>PTC Windchill</category><category>FlexPLM</category><category>RCE</category><category>Code Injection</category><category>Deserialization</category><category>Critical Manufacturing</category></item><item><title>CVE-2026-20131: Cisco FMC/SCC Deserialization Vulnerability Under Active Attack</title><link>https://runtimerebel.com/blog/cve-2026-20131-cisco-fmc-scc-deserialization-vulnerability-under-active-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-20131-cisco-fmc-scc-deserialization-vulnerability-under-active-attack</guid><description>CISA adds CVE-2026-20131, a critical deserialization vulnerability in Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC), to KEV Catalog due…</description><pubDate>Fri, 20 Mar 2026 16:21:47 GMT</pubDate><category>CVE-2026-20131</category><category>Cisco Secure Firewall Management Center</category><category>Cisco Security Cloud Control</category><category>Deserialization</category><category>KEV Catalog</category></item><item><title>CISA Catalogs Critical Roundcube Deserialization Vulnerability Under Active Exploitation</title><link>https://runtimerebel.com/blog/cisa-catalogs-critical-roundcube-deserialization-vulnerability-under-active-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-catalogs-critical-roundcube-deserialization-vulnerability-under-active-exploitation</guid><description>CISA has added CVE-2025-49113 to the Known Exploited Vulnerabilities catalog, addressing a critical RCE flaw in Roundcube webmail software resulting from untrusted data…</description><pubDate>Mon, 23 Feb 2026 04:06:31 GMT</pubDate><category>CVE-2025-49113</category><category>Roundcube</category><category>RCE</category><category>CISA KEV</category><category>Deserialization</category></item></channel></rss>