Tag: deserialization flaw
2 articles

JetBrains Cadence Breach Exposes AWS Credentials, User Data
A critical deserialization flaw, CVE-2026-63077, was exploited by unknown attackers to breach JetBrains' Cadence environment, compromising AWS credentials, backups, and user data. The vulnerability, scoring 9.8, allowed threat actors to bypass authentication and execute malicious commands with ease.

CISA Warns of Active Exploits of Microsoft SharePoint Flaw
Microsoft warns that a critical flaw in SharePoint, tracked as CVE-2026-45659, is being actively exploited, allowing even low-privilege attackers to execute arbitrary code remotely with ease. This deserialization vulnerability lets authenticated attackers run code on vulnerable servers without needing admin privileges.