{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/zmq/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-63767"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ktransformers \u003c= 0.6.3"],"_cs_severities":["critical"],"_cs_tags":["deserialization","remote-code-execution","python","zmq","vulnerability"],"_cs_type":"advisory","_cs_vendors":["kvcache-ai"],"content_html":"\u003cp\u003eA critical remote code execution (RCE) vulnerability, CVE-2026-63767, has been discovered in \u003ccode\u003ektransformers\u003c/code\u003e versions through 0.6.3. This vulnerability stems from an unauthenticated pickle deserialization flaw that affects the \u003ccode\u003eSchedulerServer ZMQ ROUTER\u003c/code\u003e socket when it is bound to all interfaces. Remote attackers can exploit this by crafting and transmitting malicious pickle payloads directly to the exposed ZMQ socket. The payloads leverage Python's \u003ccode\u003e__reduce__\u003c/code\u003e methods to embed and execute arbitrary shell commands on the system hosting \u003ccode\u003ektransformers\u003c/code\u003e. This allows attackers to gain full control over the affected server, potentially leading to data exfiltration, system integrity loss, or further network lateral movement. The vulnerability was fixed in commit \u003ccode\u003edef0f93\u003c/code\u003e and has a CVSS v3.1 base score of 9.8 (Critical).\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker identifies an internet-exposed \u003ccode\u003ektransformers\u003c/code\u003e \u003ccode\u003eSchedulerServer ZMQ ROUTER\u003c/code\u003e socket on a vulnerable server running \u003ccode\u003ektransformers\u003c/code\u003e version 0.6.3 or earlier.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a Python pickle payload specifically designed to contain malicious \u003ccode\u003e__reduce__\u003c/code\u003e methods.\u003c/li\u003e\n\u003cli\u003eThe malicious \u003ccode\u003e__reduce__\u003c/code\u003e methods are configured to invoke arbitrary system commands, such as spawning a shell or downloading additional malware.\u003c/li\u003e\n\u003cli\u003eThe crafted pickle payload is transmitted unauthenticated over the network to the vulnerable \u003ccode\u003eZMQ ROUTER\u003c/code\u003e socket.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003ektransformers\u003c/code\u003e application receives the untrusted pickle payload and initiates the deserialization process.\u003c/li\u003e\n\u003cli\u003eDuring deserialization, the Python \u003ccode\u003epickle\u003c/code\u003e module processes the malicious \u003ccode\u003e__reduce__\u003c/code\u003e method, triggering the execution of the embedded arbitrary commands.\u003c/li\u003e\n\u003cli\u003eThe arbitrary shell commands are executed on the underlying system with the privileges of the \u003ccode\u003ektransformers\u003c/code\u003e server process, achieving remote code execution and initial system compromise.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-63767 results in unauthenticated remote code execution on the server running \u003ccode\u003ektransformers\u003c/code\u003e. This critical impact means attackers can fully compromise the affected system, leading to arbitrary data modification or deletion, sensitive data exfiltration, and the ability to establish persistence or pivot to other systems within the network. Depending on the server's role and data stored, this could lead to significant operational disruption, reputational damage, and regulatory penalties. The high CVSS score of 9.8 reflects the severity of this vulnerability.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately apply the patch associated with commit \u003ccode\u003edef0f93\u003c/code\u003e or upgrade \u003ccode\u003ektransformers\u003c/code\u003e to a version past 0.6.3, as referenced in the NVD.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rules for Windows and Linux to your SIEM to detect suspicious process creation activities originating from \u003ccode\u003epython.exe\u003c/code\u003e or other \u003ccode\u003ektransformers\u003c/code\u003e related processes.\u003c/li\u003e\n\u003cli\u003eReview network firewall rules to restrict direct external access to \u003ccode\u003eZMQ ROUTER\u003c/code\u003e sockets, allowing connections only from trusted internal sources if possible.\u003c/li\u003e\n\u003cli\u003eMonitor process creation logs (e.g., Sysmon on Windows, Auditd/Procfs on Linux) for unusual child processes spawned by Python interpreters or the \u003ccode\u003ektransformers\u003c/code\u003e application.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-20T20:19:18Z","date_published":"2026-07-20T20:19:18Z","id":"https://feed.craftedsignal.io/briefs/2026-07-ktransformers-rce/","summary":"A critical unauthenticated pickle deserialization vulnerability (CVE-2026-63767) in ktransformers versions up to 0.6.3 allows remote attackers to execute arbitrary commands by sending specially crafted pickle payloads containing malicious `__reduce__` methods to the SchedulerServer ZMQ ROUTER socket, leading to complete server compromise.","title":"Critical Unauthenticated RCE in ktransformers (CVE-2026-63767)","url":"https://feed.craftedsignal.io/briefs/2026-07-ktransformers-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Zmq","version":"https://jsonfeed.org/version/1.1"}