Product
An unauthenticated remote code execution vulnerability (CVE-2026-80428) in ILIAS allows attackers to achieve arbitrary file writes and code execution by exploiting insecure deserialization within the Shibboleth logout-notification handler.