⤷ Title: Insecure Deserialization Vulnerability: From Theory to Practice
════════════════════════
𐀪 Author: Mohana Reddy
════════════════════════
ⴵ Time: Thu, 23 Jan 2025 12:31:25 GMT
════════════════════════
⌗ Tags: #vulnerability #insecure_deserialization #penetration_testing #vapt #serialization
════════════════════════
𐀪 Author: Mohana Reddy
════════════════════════
ⴵ Time: Thu, 23 Jan 2025 12:31:25 GMT
════════════════════════
⌗ Tags: #vulnerability #insecure_deserialization #penetration_testing #vapt #serialization
Medium
Insecure Deserialization Vulnerability: From Theory to Practice
Insecure deserialization is one of the most critical vulnerabilities in modern web applications, yet it’s often ignored by many security…
⤷ Title: Remote Code Execution (RCE) via Telerik RadAsyncUpload (RAU) Function Exploit
════════════════════════
𐀪 Author: Ayushi
════════════════════════
ⴵ Time: Sat, 25 Jan 2025 14:46:35 GMT
════════════════════════
⌗ Tags: #telerik #pentesting #insecure_deserialization #rce_vulnerability #cve
════════════════════════
𐀪 Author: Ayushi
════════════════════════
ⴵ Time: Sat, 25 Jan 2025 14:46:35 GMT
════════════════════════
⌗ Tags: #telerik #pentesting #insecure_deserialization #rce_vulnerability #cve
Medium
Remote Code Execution (RCE) via Telerik RadAsyncUpload (RAU) Function Exploit
Disclaimer: This blog is based on exploitation of CVE-2019–18935.
⤷ Title: Bug Bounty Hunting: Web Vulnerability (Insecure Deserialization)
════════════════════════
𐀪 Author: Muhammad Abdullah Niazi
════════════════════════
ⴵ Time: Wed, 12 Feb 2025 10:28:59 GMT
════════════════════════
⌗ Tags: #bug_bounty_hunter #insecure_deserialization #bug_bounty_tips #bug_bounty #bug_bounty_program
════════════════════════
𐀪 Author: Muhammad Abdullah Niazi
════════════════════════
ⴵ Time: Wed, 12 Feb 2025 10:28:59 GMT
════════════════════════
⌗ Tags: #bug_bounty_hunter #insecure_deserialization #bug_bounty_tips #bug_bounty #bug_bounty_program
Medium
Bug Bounty Hunting: Web Vulnerability (Insecure Deserialization)
Mastering Insecure Deserialization: Techniques, Bypasses, and Exploits
⤷ Title: TryHackMe: writeup Debug
════════════════════════
𐀪 Author: b4sh
════════════════════════
ⴵ Time: Wed, 26 Feb 2025 17:28:13 GMT
════════════════════════
⌗ Tags: #hacking #ctf_writeup #tryhackme_writeup #insecure_deserialization
════════════════════════
𐀪 Author: b4sh
════════════════════════
ⴵ Time: Wed, 26 Feb 2025 17:28:13 GMT
════════════════════════
⌗ Tags: #hacking #ctf_writeup #tryhackme_writeup #insecure_deserialization
Medium
TryHackMe: writeup Debug
https://tryhackme.com/room/debug
⤷ Title: Hijacking Trust: The Parallels Between Use-After-Free and Insecure Deserialization
════════════════════════
𐀪 Author: Masoud Abdaal
════════════════════════
ⴵ Time: Thu, 24 Apr 2025 04:06:56 GMT
════════════════════════
⌗ Tags: #exploit #insecure_deserialization #bug_bounty #c_programming #heap_memory
════════════════════════
𐀪 Author: Masoud Abdaal
════════════════════════
ⴵ Time: Thu, 24 Apr 2025 04:06:56 GMT
════════════════════════
⌗ Tags: #exploit #insecure_deserialization #bug_bounty #c_programming #heap_memory
Medium
Hijacking Trust: The Parallels Between Use-After-Free and Insecure Deserialization
Summary
⤷ Title: Insecure Deserialization : An Introduction
════════════════════════
𐀪 Author: Yash Radhakrishna
════════════════════════
ⴵ Time: Tue, 13 May 2025 04:58:41 GMT
════════════════════════
⌗ Tags: #business_logic_flaw #web_security #cybersecurity #insecure_deserialization
════════════════════════
𐀪 Author: Yash Radhakrishna
════════════════════════
ⴵ Time: Tue, 13 May 2025 04:58:41 GMT
════════════════════════
⌗ Tags: #business_logic_flaw #web_security #cybersecurity #insecure_deserialization
Medium
Insecure Deserialization : An Introduction
So, in today’s article, I’m going to write about Insecure Deserialization, what it is, and what I know about it.
Heads up, I’ve studied…
Heads up, I’ve studied…
⤷ Title: Tryhackme | OWASP Top Ten — 2017 | Day — 8 Insecure Deserialization | walkthrough
════════════════════════
𐀪 Author: Sudarshan Patel
════════════════════════
ⴵ Time: Fri, 16 May 2025 12:06:03 GMT
════════════════════════
⌗ Tags: #insecure_deserialization #tryhackme #tryhackme_walkthrough #owasp_top_10 #tryhackme_writeup
════════════════════════
𐀪 Author: Sudarshan Patel
════════════════════════
ⴵ Time: Fri, 16 May 2025 12:06:03 GMT
════════════════════════
⌗ Tags: #insecure_deserialization #tryhackme #tryhackme_walkthrough #owasp_top_10 #tryhackme_writeup
Medium
Tryhackme | OWASP Top Ten — 2017 | Day — 8 Insecure Deserialization | walkthrough
Hey there, fellow hackers! Ready to dive into Day 8 of TryHackMe’s OWASP Top 10 2017 adventure? Today, our mission is to unravel the…
⤷ Title: TOMCAT RCE(CVE-2025–24813)
════════════════════════
𐀪 Author: Taha Hisoglu
════════════════════════
ⴵ Time: Thu, 12 Jun 2025 00:14:27 GMT
════════════════════════
⌗ Tags: #tomcat #cve_2025_24813 #insecure_deserialization #rce_vulnerability #cybersecurity
════════════════════════
𐀪 Author: Taha Hisoglu
════════════════════════
ⴵ Time: Thu, 12 Jun 2025 00:14:27 GMT
════════════════════════
⌗ Tags: #tomcat #cve_2025_24813 #insecure_deserialization #rce_vulnerability #cybersecurity
Medium
TOMCAT RCE(CVE-2025–24813)
Yakın geçmişteki zafiyetleri incelerken Tomcat’de bulunan CVE-2025–24813 gözüme çarptı ve incelemeye karar verdim. Zafiyet CVSS skoru 9.8…
⤷ Title: Insecure Deserialization in Symfony: A Real Threat
════════════════════════
𐀪 Author: Pentest_Testing_Corp
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 08:50:37 GMT
════════════════════════
⌗ Tags: #vulnerability #penetration_testing #symfony #insecure_deserialization #cybersecurity
════════════════════════
𐀪 Author: Pentest_Testing_Corp
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 08:50:37 GMT
════════════════════════
⌗ Tags: #vulnerability #penetration_testing #symfony #insecure_deserialization #cybersecurity
Medium
Insecure Deserialization in Symfony: A Real Threat
Symfony, a widely adopted PHP framework, offers powerful features and flexibility for web applications. However, like many complex…
⤷ Title: SAP’s July 2025 Patch Day Brings 27 New Notes, Multiple Critical RCE & Deserialization Flaws (CVSS 10.0)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 07:40:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authorization Bypass #CVE_2025_30009 #CVE_2025_42967 #Enterprise Portal #Insecure Deserialization #Live Auction Cockpit #NetWeaver #rce #Remote Code Execution #S/4HANA #SAP #security patch #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 07:40:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authorization Bypass #CVE_2025_30009 #CVE_2025_42967 #Enterprise Portal #Insecure Deserialization #Live Auction Cockpit #NetWeaver #rce #Remote Code Execution #S/4HANA #SAP #security patch #Vulnerability
Daily CyberSecurity
SAP's July 2025 Patch Day Brings 27 New Notes, Multiple Critical RCE & Deserialization Flaws (CVSS 10.0)
SAP's July 2025 Patch Day fixes 27 vulnerabilities, including critical RCE (CVSS 10.0) in Live Auction Cockpit and multiple insecure deserialization flaws (CVSS 9.1) across NetWeaver components.
⤷ Title: Symantec Endpoint Management Alert: Critical Flaw Allows Unauthenticated RCE, PoC Releases
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 14 Jul 2025 10:58:57 +0000
════════════════════════
⌗ Tags: #Vulnerability #Altiris #cybersecurity #Endpoint Management #Insecure Deserialization #rce #Remote Code Execution #Symantec
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 14 Jul 2025 10:58:57 +0000
════════════════════════
⌗ Tags: #Vulnerability #Altiris #cybersecurity #Endpoint Management #Insecure Deserialization #rce #Remote Code Execution #Symantec
Daily CyberSecurity
Symantec Endpoint Management Alert: Critical Flaw Allows Unauthenticated RCE, PoC Releases
A critical RCE flaw (CVE-2025-5333) in Symantec Endpoint Management (Altiris) allows unauthenticated attackers to execute arbitrary code via insecure .NET Remoting deserialization.
⤷ Title: Insecure Deserialization — Overview
════════════════════════
𐀪 Author: Yassin Khadrawy
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 21:30:10 GMT
════════════════════════
⌗ Tags: #penetration_testing #insecure_deserialization #pentesting #cybersecurity #insecurity
════════════════════════
𐀪 Author: Yassin Khadrawy
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 21:30:10 GMT
════════════════════════
⌗ Tags: #penetration_testing #insecure_deserialization #pentesting #cybersecurity #insecurity
Medium
Insecure Deserialization — Overview
Serialization and deserialization are common operations in modern web applications. But when misused, they open the door to one of the…
⤷ Title: Tryhackme: React2Shell
════════════════════════
𐀪 Author: sagar ujalambkar
════════════════════════
ⴵ Time: Wed, 31 Dec 2025 06:12:16 GMT
════════════════════════
⌗ Tags: #reactjs #insecure_deserialization #cve_2025_55182 #tryhackme #websecurity_testing
════════════════════════
𐀪 Author: sagar ujalambkar
════════════════════════
ⴵ Time: Wed, 31 Dec 2025 06:12:16 GMT
════════════════════════
⌗ Tags: #reactjs #insecure_deserialization #cve_2025_55182 #tryhackme #websecurity_testing
Medium
Tryhackme: React2Shell
What is React2Shell Vulnerability?
This vulnerability affects React Server Components (RSC) and the frameworks that implement them…
This vulnerability affects React Server Components (RSC) and the frameworks that implement them…
⤷ Title: The Complete Guide to ASP.NET ViewState Exploitation
════════════════════════
𐀪 Author: Dipesh Paul
════════════════════════
ⴵ Time: Thu, 15 Jan 2026 14:45:10 GMT
════════════════════════
⌗ Tags: #rce #insecure_deserialization #cybersecurity #aspnetcore #hacking
════════════════════════
𐀪 Author: Dipesh Paul
════════════════════════
ⴵ Time: Thu, 15 Jan 2026 14:45:10 GMT
════════════════════════
⌗ Tags: #rce #insecure_deserialization #cybersecurity #aspnetcore #hacking
Medium
The Complete Guide to ASP.NET ViewState Exploitation
How I spent hours trying to exploit ViewState deserialization, failed spectacularly, and learned valuable lessons about ASP.NET security in…
⤷ Title: HTB: Outbound
════════════════════════
𐀪 Author: bluesnow
════════════════════════
ⴵ Time: Tue, 17 Feb 2026 07:42:30 GMT
════════════════════════
⌗ Tags: #roundcube #rce #below #insecure_deserialization #symlink_attack
════════════════════════
𐀪 Author: bluesnow
════════════════════════
ⴵ Time: Tue, 17 Feb 2026 07:42:30 GMT
════════════════════════
⌗ Tags: #roundcube #rce #below #insecure_deserialization #symlink_attack
Medium
HTB: Outbound
| Roundcube | PHP Deserialization | CVE-2025–49113 | 3DES Hash Decryption | Below | Symlink Attack |
⤷ Title: Critical 10.0 CVSS Flaw in Cisco Secure FMC Hands Hackers Root Access to Enterprise Firewalls
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 05 Mar 2026 01:37:24 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cisco Secure FMC #CVE_2026_20131 #CVSS 10.0 #firewall security #infosec #Insecure Deserialization #Patch Alert #Remote Code Execution #unauthenticated RCE #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 05 Mar 2026 01:37:24 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cisco Secure FMC #CVE_2026_20131 #CVSS 10.0 #firewall security #infosec #Insecure Deserialization #Patch Alert #Remote Code Execution #unauthenticated RCE #Vulnerability
Daily CyberSecurity
Critical 10.0 CVSS Flaw in Cisco Secure FMC Hands Hackers Root Access to Enterprise Firewalls
A critical 10.0 CVSS unauthenticated RCE flaw (CVE-2026-20131) in Cisco Secure FMC allows hackers root access via insecure Java deserialization. Patch now.
⤷ Title: Critical Alert: SAP’s Latest Security Update Fixes 9.8 CVSS RCE and Deserialization Flaws
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 07:20:40 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2019_17571 #CVE_2026_27685 #cybersecurity #Enterprise Security #infosec #Insecure Deserialization #Patch Tuesday #Remote Code Execution #SAP Security #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 07:20:40 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2019_17571 #CVE_2026_27685 #cybersecurity #Enterprise Security #infosec #Insecure Deserialization #Patch Tuesday #Remote Code Execution #SAP Security #Vulnerability
Daily CyberSecurity
Critical Alert: SAP's Latest Security Update Fixes 9.8 CVSS RCE and Deserialization Flaws
SAP's latest security update addresses 15 flaws, including critical RCE (CVE-2019-17571) and deserialization (CVE-2026-27685) vulnerabilities. Patch now.
⤷ Title: CVE-2026-34838 (CVSS 10): Critical RCE Flaw Uncovered in GroupOffice CRM
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 06 Apr 2026 14:03:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CRM Security #CVE_2026_34838 #GroupOffice #Guzzle #infosec #Insecure Deserialization #PHP Security #POP Chain #rce #Vulnerability Research #Web Shell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 06 Apr 2026 14:03:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CRM Security #CVE_2026_34838 #GroupOffice #Guzzle #infosec #Insecure Deserialization #PHP Security #POP Chain #rce #Vulnerability Research #Web Shell
Daily CyberSecurity
CVE-2026-34838 (CVSS 10): Critical RCE Flaw Uncovered in GroupOffice CRM
CVE-2026-34838: A critical 10.0 flaw in GroupOffice allows authenticated users to trigger RCE via insecure deserialization. Update to v26.0.12 immediately!
⤷ Title: Unauthenticated RCE via WebLogic WLS-WSAT (CVE-2019–2725)
════════════════════════
𐀪 Author: Sai
════════════════════════
ⴵ Time: Fri, 08 May 2026 08:02:20 GMT
════════════════════════
⌗ Tags: #insecure_deserialization #oracle_weblogic_server #vulnerability #application_security #remote_code_execution
════════════════════════
𐀪 Author: Sai
════════════════════════
ⴵ Time: Fri, 08 May 2026 08:02:20 GMT
════════════════════════
⌗ Tags: #insecure_deserialization #oracle_weblogic_server #vulnerability #application_security #remote_code_execution
Medium
Unauthenticated RCE via WebLogic WLS-WSAT (CVE-2019–2725)
Overview
⤷ Title: Remote Code Execution via Insecure Deserialization in Wazuh XDR/SIEM (CVE-2026–25769)
════════════════════════
𐀪 Author: Kevin Dicks
════════════════════════
ⴵ Time: Sun, 10 May 2026 22:24:11 GMT
════════════════════════
⌗ Tags: #cve #insecure_deserialization #rce
════════════════════════
𐀪 Author: Kevin Dicks
════════════════════════
ⴵ Time: Sun, 10 May 2026 22:24:11 GMT
════════════════════════
⌗ Tags: #cve #insecure_deserialization #rce
Medium
Remote Code Execution via Insecure Deserialization in Wazuh XDR/SIEM (CVE-2026–25769)
Abstract