CWE-502 可信数据的反序列化 类弱点 2189 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-502 指反序列化不可信数据漏洞,属于数据验证缺陷。攻击者通过构造恶意序列化对象,在系统反序列化时触发任意代码执行或拒绝服务。开发者应避免直接反序列化外部输入,改用 JSON 等安全格式,或实施严格的类白名单校验与完整性检查,确保反序列化过程仅处理预期类型,从而阻断恶意载荷执行。
try { File file = new File("object.obj"); ObjectInputStream in = new ObjectInputStream(new FileInputStream(file)); javax.swing.JButton button = (javax.swing.JButton) in.readObject(); in.close(); }
private final void readObject(ObjectInputStream in) throws java.io.IOException { throw new java.io.IOException("Cannot be deserialized"); }
try { class ExampleProtocol(protocol.Protocol): def dataReceived(self, data): # Code that would be here would parse the incoming data # After receiving headers, call confirmAuth() to authenticate def confirmAuth(self, headers): try: token = cPickle.loads(base64.b64decode(headers['AuthToken'])) if not check_hmac(token['signature'], token['data'], getSecretKey()): raise AuthFail self.secure_data = token['data'] except: raise AuthFail }
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2026-66808 | Microsoft SharePoint 反序列化注入漏洞 — Microsoft SharePoint Enterprise Server 2016 | 8.8 | High | 2026-08-11 |
| CVE-2026-66805 | Microsoft SharePoint 反序列化注入漏洞 — Microsoft SharePoint Enterprise Server 2016 | 8.8 | High | 2026-08-11 |
| CVE-2026-64901 | Microsoft SharePoint 反序列化注入漏洞 — Microsoft SharePoint Enterprise Server 2016 | 8.8 | High | 2026-08-11 |
| CVE-2026-70321 | Microsoft SharePoint 反序列化注入漏洞 — Microsoft SharePoint Server Subscription Edition | 8.8 | High | 2026-08-11 |
| CVE-2026-65815 | Microsoft Dynamics 365 反序列化注入漏洞 — Microsoft Dynamics 365 (on-premises) version 9.1 | 8.8 | High | 2026-08-11 |
| CVE-2026-65665 | Microsoft SharePoint 反序列化注入漏洞 — Microsoft SharePoint Server 2019 | 8.8 | High | 2026-08-11 |
| CVE-2026-65663 | Microsoft SharePoint 反序列化注入漏洞 — Microsoft SharePoint Enterprise Server 2016 | 8.8 | High | 2026-08-11 |
| CVE-2026-65658 | Microsoft SharePoint 反序列化注入漏洞 — Microsoft SharePoint Enterprise Server 2016 | 8.8 | High | 2026-08-11 |
| CVE-2026-62912 | Microsoft Exchange Server 反序列化注入漏洞 — Microsoft Exchange Server 2016 Cumulative Update 23 | 6.5 | Medium | 2026-08-11 |
| CVE-2026-59124 | Microsoft Windows App Client for Windows Desktop 反序列化注入漏洞 — Microsoft HPC Pack 2019 | 9.8 | Critical | 2026-08-11 |
| CVE-2026-63516 | Microsoft SharePoint 反序列化注入漏洞 — Microsoft SharePoint Enterprise Server 2016 | 6.5 | Medium | 2026-08-11 |
| CVE-2026-63514 | Microsoft SharePoint 反序列化注入漏洞 — Microsoft SharePoint Enterprise Server 2016 | 8.8 | High | 2026-08-11 |
| CVE-2026-17061 | Dassault Systèmes SIMULIA Execution Engine 反序列化注入漏洞 — SIMULIA Execution Engine | 10.0 | Critical | 2026-08-11 |
| CVE-2026-15555 | JBoss Marshalling 反序列化注入漏洞 — Red Hat JBoss Enterprise Application Platform 7.4.25 | 8.8 | High | 2026-08-11 |
| CVE-2026-69659 | Ash Framework 反序列化漏洞 — ash | 5.9 | Medium | 2026-08-09 |
| CVE-2026-68772 | ZenML 反序列化注入漏洞 — ZenML | 8.0 | High | 2026-08-07 |
| CVE-2026-71559 | Apache Fory C++ 反序列化注入漏洞 — Apache Fory | - | - | 2026-08-07 |
| CVE-2026-71558 | Apache Fory C++ 反序列化注入漏洞 — Apache Fory | - | - | 2026-08-07 |
| CVE-2026-71560 | Apache Fory C++ 反序列化漏洞 — Apache Fory | - | - | 2026-08-07 |
| CVE-2026-50515 | Microsoft Azure Service Bus 反序列化注入漏洞 — Azure Service Bus | 9.9 | Critical | 2026-08-06 |
| CVE-2026-65581 | WordPress Anna Lite 反序列化注入漏洞 — AI ANN | 9.8 | Critical | 2026-08-06 |
| CVE-2026-65579 | AxiomThemes agricola 反序列化注入漏洞 — Agricola | 9.8 | Critical | 2026-08-06 |
| CVE-2026-65577 | AncoraThemes Advice 反序列化漏洞 — Advice | 9.8 | Critical | 2026-08-06 |
| CVE-2026-65578 | AncoraThemes Agora 反序列化漏洞 — Agora | 9.8 | Critical | 2026-08-06 |
| CVE-2026-65576 | AncoraThemes Adrena 反序列化注入漏洞 — Adrena | 9.8 | Critical | 2026-08-06 |
| CVE-2026-65574 | AncoraThemes Abogado 反序列化注入漏洞 — Abogado | 9.8 | Critical | 2026-08-06 |
| CVE-2026-65575 | AncoraThemes Accalia 反序列化漏洞 — Accalia | 9.8 | Critical | 2026-08-06 |
| CVE-2026-65573 | Themerex Abelle 反序列化注入漏洞 — Abelle | 9.8 | Critical | 2026-08-06 |
| CVE-2026-65571 | WordPress 69 Clothing 反序列化注入漏洞 — 69 Clothing | 9.8 | Critical | 2026-08-06 |
| CVE-2026-65572 | AxiomThemes A.Williams 反序列化漏洞 — A.Williams | 9.8 | Critical | 2026-08-06 |
CWE-502(可信数据的反序列化) 是常见的弱点类别,本平台收录该类弱点关联的 2189 条 CVE 漏洞。