Tag
critical
advisory
IBM WebSphere Application Server Authentication Bypass Vulnerability (CVE-2026-16184)
5 TTPs 7 CVEs 5 IOCsA remote attacker can bypass authentication in IBM WebSphere Application Server versions 9.0 and 8.5 by sending a crafted unauthenticated request, potentially leading to unauthorized access and impact on confidentiality, integrity, and availability.
WebSphere Application Server 9.0 +8
vulnerability
authentication-bypass
websphere
broken-access-control
privilege-escalation
deserialization
RCE
server-side-request-forgery
+6
5t
7c
5i
high
advisory
Stanza: Remote Code Execution via Unsafe Pickle Deserialization in Model Loaders
2 rules 2 TTPsStanza, an NLP library, is vulnerable to remote code execution (CVE-2026-54499) due to an unsafe fallback mechanism when loading PyTorch model files, allowing an attacker who can place a malicious pretrain or model file to achieve arbitrary code execution on systems processing NLP pipelines, leading to credential theft, backdoors, data exfiltration, and lateral movement.
Stanza +1
deserialization
rce
python
pytorch
machine-learning
supply-chain
cwe-502
nlp
+1
2r
2t