View Ridge Security
Back to Cyber HoseVulnerabilities & CVEs

Critical RCE in LMDeploy via Unsafe Pickle Deserialization

🔓 CVEs & KEV

  • CVE-2026-76850 — CVSS 9.3 — LMDeploy Remote Code Execution via Unsafe Pickle Deserialization in the Disag...

  • CVE-2026-76404 — CVSS 9.1 — Remote Code Execution (RCE) through Deserialization of Untrusted Data in Splu...

  • CVE-2026-76395 — CVSS 8.8 — Remote Code Execution (RCE) through Deserialization of Untrusted Data in the ...

  • CVE-2026-76389 — CVSS 8.8 — Server-Side Request Forgery (SSRF) through the REST API in Cisco Talos Intell...

  • CVE-2026-76584 — CVSS 8.6 — TRENDnet TV-IP751WIC Stack-Based Buffer Overflow (CVE-2026-76584)

  • CVE-2026-76394 — CVSS 8.3 — Missing Authorization in Container and Connection Management through the REST...

  • CVE-2026-76391 — CVSS 8.3 — Improper Privilege Management through Agent Run History in Splunk AI ToolkitI...

  • CVE-2026-76402 — CVSS 8.2 — Server-Side Request Forgery (SSRF) through the REST API in Splunk Connect for...

  • CVE-2026-76399 — CVSS 8.1 — Incorrect Permission Assignment for Scheduled Searches in Splunk AI ToolkitIn...

  • CVE-2026-76397 — CVSS 8.1 — Improper Access Control in Experiment History through the REST API in Splunk ...

  • CVE-2026-76396 — CVSS 7.5 — Improper Access Control through Scheduled Searches in Splunk AI ToolkitIn Spl...

  • CVE-2026-76403 — CVSS 7.4 — Improper Certificate Validation through HTTP Event Collector Kerberos Authent...

  • CVE-2026-63123 — CVSS 6.5 — Tina: Cross-origin POST /media/upload/* requests can write arbitrary files ...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check