Threadlinqs IntelligenceStart free

Weakness · BaseCWE-502

CWE-502: Deserialization of Untrusted Data

Likelihood of exploit: MediumKEV-linkedBase

As of 2026-10-05, CWE-502 (Deserialization of Untrusted Data) underlies 66 CVEs tracked by Threadlinqs, 20 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 164 tracked threats. MITRE rates its likelihood of exploit as Medium.

CVEs
66Mapped to CWE-502
CISA KEV
20Exploited in the wild
Critical
40CVSS v3 critical CVEs
Threats
164Tracked campaigns citing it
Likelihood
MediumMITRE likelihood of exploit

Last updated:

What is CWE-502?

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

CWE-502 is a base-level weakness in MITRE’s Common Weakness Enumeration, with a MITRE likelihood of exploit of Medium. Applicable platforms: Language: Java; Language: Ruby; Language: PHP; Language: Python; Language: JavaScript; Technology: Not Technology-Specific.

Source: MITRE CWE (CWE-502 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Integrity — Modify Application Data, Unexpected State. Attackers can modify unexpected objects or data that was assumed to be safe from modification. Deserialized data or code could be modified without using the provided accessor functions, or unexpected functions could be invoked.
  • Availability — DoS: Resource Consumption (CPU). If a function is making an assumption on when to terminate, based on a sentry in a string, it could easily never terminate.
  • Other — Varies by Context. The consequences can vary widely, because it depends on which objects or methods are being deserialized, and how they are used. Making an assumption that the code in the deserialized object is valid is dangerous and can enable exploitation. One example is attackers using gadget chains to perform unauthorized actions, such as generating a shell.

Source: MITRE CWE, common consequences.

How CWE-502 is exploited in the wild

Threadlinqs maps 66 CVEs to CWE-502, published between 2019-12-11 and 2026-09-29. 20 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 11 are tied to ransomware campaigns. By CVSS v3 severity the set splits into 40 critical, 19 high, 5 medium. The highest EPSS score in the set is 99.9% (CVE-2023-0669), the modelled probability of exploitation in the next 30 days. 164 tracked threats reference CWE-502 directly or through a CVE it covers; the most recent is “The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira, REDBIKE, AGENDA)” (2026-10-03). Affected products concentrate in Microsoft (11), Solarwinds (8), Oracle Corporation (6), among 34 vendors in total.

Vulnerabilities (CVEs)

Showing 40 of 66 CVEs mapped to CWE-502, CISA KEV first, then by CVSS score.

  • CVE-2023-46604 — CISA KEV · CVSS 10 critical · EPSS 94.4% · published 2023-10-27
  • CVE-2021-44228 — CISA KEV · CVSS 10 critical · EPSS 94.3% · published 2021-12-10
  • CVE-2025-55182 — CISA KEV · CVSS 10 critical · EPSS 84.8% · published 2025-12-03
  • CVE-2025-10035 — CISA KEV · CVSS 10 critical · EPSS 55.7% · published 2025-09-18
  • CVE-2026-20131 — CISA KEV · CVSS 10 critical · EPSS 0.7% · published 2026-03-04
  • CVE-2025-49113 — CISA KEV · CVSS 9.9 critical · EPSS 91.5% · published 2025-06-02
  • CVE-2020-10189 — CISA KEV · CVSS 9.8 critical · EPSS 94.2% · published 2020-03-06
  • CVE-2019-18935 — CISA KEV · CVSS 9.8 critical · EPSS 93.5% · published 2019-12-11
  • CVE-2025-53770 — CISA KEV · CVSS 9.8 critical · EPSS 89.9% · published 2025-07-20
  • CVE-2025-40551 — CISA KEV · CVSS 9.8 critical · EPSS 89.9% · published 2026-01-28
  • CVE-2024-28986 — CISA KEV · CVSS 9.8 critical · EPSS 75.0% · published 2024-08-13
  • CVE-2024-40711 — CISA KEV · CVSS 9.8 critical · EPSS 68.1% · published 2024-09-07
  • CVE-2025-26399 — CISA KEV · CVSS 9.8 critical · EPSS 32.2% · published 2025-09-23
  • CVE-2026-12569 — CISA KEV · CVSS 9.8 critical · EPSS 1.1% · published 2026-06-18
  • CVE-2026-20265 — CISA KEV · CVSS 9.8 critical
  • CVE-2026-20963 — CISA KEV · CVSS 8.8 high · EPSS 6.4% · published 2026-01-13
  • CVE-2021-23758 — CISA KEV · CVSS 8.1 high · EPSS 82.5% · published 2021-12-03
  • CVE-2022-41082 — CISA KEV · CVSS 8 high · EPSS 90.7% · published 2022-10-03
  • CVE-2021-26857 — CISA KEV · CVSS 7.8 high · EPSS 44.7% · published 2021-03-03
  • CVE-2023-0669 — CISA KEV · CVSS 7.2 high · EPSS 99.9% · published 2023-02-06
  • CVE-2026-69836 — CVSS 10 critical · EPSS 1.3% · published 2026-08-20
  • CVE-2026-82222 — CVSS 10 critical · EPSS 0.4% · published 2026-08-28
  • CVE-2026-60366 — CVSS 10 critical · published 2026-07-22
  • CVE-2026-87719 — CVSS 9.9 critical · EPSS 0.6% · published 2026-09-12
  • CVE-2026-60369 — CVSS 9.9 critical · EPSS 0.4% · published 2026-07-22
  • CVE-2025-40553 — CVSS 9.8 critical · EPSS 14.4% · published 2026-01-28
  • CVE-2024-28988 — CVSS 9.8 critical · EPSS 9.7% · published 2025-09-01
  • CVE-2026-56700 — CVSS 9.8 critical · EPSS 1.6% · published 2026-06-30
  • CVE-2026-58644 — CVSS 9.8 critical · EPSS 1.3% · published 2026-07-14
  • CVE-2026-40860 — CVSS 9.8 critical · EPSS 0.8% · published 2026-04-27
  • CVE-2026-63077 — CVSS 9.8 critical · EPSS 0.6% · published 2026-07-27
  • CVE-2026-60367 — CVSS 9.8 critical · EPSS 0.5% · published 2026-07-22
  • CVE-2026-60372 — CVSS 9.8 critical · EPSS 0.5% · published 2026-07-22
  • CVE-2026-53874 — CVSS 9.8 critical · EPSS 0.5% · published 2026-06-17
  • CVE-2026-18163 — CVSS 9.8 critical · EPSS 0.5% · published 2026-09-22
  • CVE-2026-103040 — CVSS 9.8 critical · published 2026-09-29
  • CVE-2026-103041 — CVSS 9.8 critical · published 2026-09-29
  • CVE-2026-50522 — CVSS 9.8 critical · published 2026-07-14
  • CVE-2026-78265 — CVSS 9.8 critical · published 2026-08-24
  • CVE-2024-28074 — CVSS 9.6 critical · EPSS 0.1% · published 2024-07-17

Affected vendors

Threat activity

164 tracked threats cite CWE-502; the 25 most recent are listed.

Mitigations

  • Architecture and Design, Implementation: If available, use the signing/sealing features of the programming language to assure that deserialized data has not been tainted. For example, a hash-based message authentication code (HMAC) could be used to ensure that data has not been modified.
  • Implementation: When deserializing data, populate a new object rather than just deserializing. The result is that the data flows through safe input validation and that the functions are safe.
  • Implementation: Explicitly define a final object() to prevent deserialization.
  • Architecture and Design, Implementation: Make fields transient to protect them from deserialization. An attempt to serialize and then deserialize a class containing transient fields will result in NULLs where the transient data should be. This is an excellent way to prevent time, environment-based, or sensitive variables from being carried over and used improperly.
  • Implementation: Avoid having unnecessary types or gadgets (a sequence of instances and method invocations that can self-execute during the deserialization process, often found in libraries) available that can be leveraged for malicious ends. This limits the potential for unintended or unauthorized types and gadgets to be leveraged by the attacker. Add only acceptable classes to an allowlist. Note: new gadgets are constantly being discovered, so this alone is not a sufficient mitigation.
  • Architecture and Design, Implementation: Employ cryptography of the data or code for protection. However, it's important to note that it would still be client-side security. This is risky because if the client is compromised then the security implemented on the client (the cryptography) can be bypassed.
  • Operation / Firewall: Use an application firewall that can detect attacks against this weakness. It can be beneficial in cases in which the code cannot be fixed (because it is controlled by a third party), as an emergency prevention measure while more comprehensive software assurance measures are applied, or to provide defense in depth [REF-1481].

Source: MITRE CWE, potential mitigations.

Detection methods (MITRE CWE)

  • Automated Static Analysis (effectiveness: High): Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.