# CWE-502: Deserialization of Untrusted Data

**Likelihood of exploit:** Medium · **KEV-linked**

> As of 2026-10-05, CWE-502 (Deserialization of Untrusted Data) underlies 66 CVEs tracked by Threadlinqs, 20 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 164 tracked threats. MITRE rates its likelihood of exploit as Medium.

**Last updated:** 2026-10-05

## What is CWE-502?

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

CWE-502 is a base-level weakness in MITRE’s Common Weakness Enumeration, with a MITRE likelihood of exploit of Medium. Applicable platforms: Language: Java; Language: Ruby; Language: PHP; Language: Python; Language: JavaScript; Technology: Not Technology-Specific.

_Source: [MITRE CWE](https://cwe.mitre.org/data/definitions/502.html) (CWE-502 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data._

## Consequences

- **Integrity** — Modify Application Data, Unexpected State. Attackers can modify unexpected objects or data that was assumed to be safe from modification. Deserialized data or code could be modified without using the provided accessor functions, or unexpected functions could be invoked.
- **Availability** — DoS: Resource Consumption (CPU). If a function is making an assumption on when to terminate, based on a sentry in a string, it could easily never terminate.
- **Other** — Varies by Context. The consequences can vary widely, because it depends on which objects or methods are being deserialized, and how they are used. Making an assumption that the code in the deserialized object is valid is dangerous and can enable exploitation. One example is attackers using gadget chains to perform unauthorized actions, such as generating a shell.

_Source: MITRE CWE, common consequences._

## How CWE-502 is exploited in the wild

Threadlinqs maps 66 CVEs to CWE-502, published between 2019-12-11 and 2026-09-29. 20 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 11 are tied to ransomware campaigns. By CVSS v3 severity the set splits into 40 critical, 19 high, 5 medium. The highest EPSS score in the set is 99.9% (CVE-2023-0669), the modelled probability of exploitation in the next 30 days. 164 tracked threats reference CWE-502 directly or through a CVE it covers; the most recent is “The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira, REDBIKE, AGENDA)” (2026-10-03). Affected products concentrate in Microsoft (11), Solarwinds (8), Oracle Corporation (6), among 34 vendors in total.

## Vulnerabilities (CVEs)

Showing 40 of 66 CVEs mapped to CWE-502, CISA KEV first, then by CVSS score.

- [CVE-2023-46604](https://intel.threadlinqs.com/cve/CVE-2023-46604) — CISA KEV · CVSS 10 critical · EPSS 94.4% · published 2023-10-27
- [CVE-2021-44228](https://intel.threadlinqs.com/cve/CVE-2021-44228) — CISA KEV · CVSS 10 critical · EPSS 94.3% · published 2021-12-10
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182) — CISA KEV · CVSS 10 critical · EPSS 84.8% · published 2025-12-03
- [CVE-2025-10035](https://intel.threadlinqs.com/cve/CVE-2025-10035) — CISA KEV · CVSS 10 critical · EPSS 55.7% · published 2025-09-18
- [CVE-2026-20131](https://intel.threadlinqs.com/cve/CVE-2026-20131) — CISA KEV · CVSS 10 critical · EPSS 0.7% · published 2026-03-04
- [CVE-2025-49113](https://intel.threadlinqs.com/cve/CVE-2025-49113) — CISA KEV · CVSS 9.9 critical · EPSS 91.5% · published 2025-06-02
- [CVE-2020-10189](https://intel.threadlinqs.com/cve/CVE-2020-10189) — CISA KEV · CVSS 9.8 critical · EPSS 94.2% · published 2020-03-06
- [CVE-2019-18935](https://intel.threadlinqs.com/cve/CVE-2019-18935) — CISA KEV · CVSS 9.8 critical · EPSS 93.5% · published 2019-12-11
- [CVE-2025-53770](https://intel.threadlinqs.com/cve/CVE-2025-53770) — CISA KEV · CVSS 9.8 critical · EPSS 89.9% · published 2025-07-20
- [CVE-2025-40551](https://intel.threadlinqs.com/cve/CVE-2025-40551) — CISA KEV · CVSS 9.8 critical · EPSS 89.9% · published 2026-01-28
- [CVE-2024-28986](https://intel.threadlinqs.com/cve/CVE-2024-28986) — CISA KEV · CVSS 9.8 critical · EPSS 75.0% · published 2024-08-13
- [CVE-2024-40711](https://intel.threadlinqs.com/cve/CVE-2024-40711) — CISA KEV · CVSS 9.8 critical · EPSS 68.1% · published 2024-09-07
- [CVE-2025-26399](https://intel.threadlinqs.com/cve/CVE-2025-26399) — CISA KEV · CVSS 9.8 critical · EPSS 32.2% · published 2025-09-23
- [CVE-2026-12569](https://intel.threadlinqs.com/cve/CVE-2026-12569) — CISA KEV · CVSS 9.8 critical · EPSS 1.1% · published 2026-06-18
- [CVE-2026-20265](https://intel.threadlinqs.com/cve/CVE-2026-20265) — CISA KEV · CVSS 9.8 critical
- [CVE-2026-20963](https://intel.threadlinqs.com/cve/CVE-2026-20963) — CISA KEV · CVSS 8.8 high · EPSS 6.4% · published 2026-01-13
- [CVE-2021-23758](https://intel.threadlinqs.com/cve/CVE-2021-23758) — CISA KEV · CVSS 8.1 high · EPSS 82.5% · published 2021-12-03
- [CVE-2022-41082](https://intel.threadlinqs.com/cve/CVE-2022-41082) — CISA KEV · CVSS 8 high · EPSS 90.7% · published 2022-10-03
- [CVE-2021-26857](https://intel.threadlinqs.com/cve/CVE-2021-26857) — CISA KEV · CVSS 7.8 high · EPSS 44.7% · published 2021-03-03
- [CVE-2023-0669](https://intel.threadlinqs.com/cve/CVE-2023-0669) — CISA KEV · CVSS 7.2 high · EPSS 99.9% · published 2023-02-06
- [CVE-2026-69836](https://intel.threadlinqs.com/cve/CVE-2026-69836) — CVSS 10 critical · EPSS 1.3% · published 2026-08-20
- [CVE-2026-82222](https://intel.threadlinqs.com/cve/CVE-2026-82222) — CVSS 10 critical · EPSS 0.4% · published 2026-08-28
- [CVE-2026-60366](https://intel.threadlinqs.com/cve/CVE-2026-60366) — CVSS 10 critical · published 2026-07-22
- [CVE-2026-87719](https://intel.threadlinqs.com/cve/CVE-2026-87719) — CVSS 9.9 critical · EPSS 0.6% · published 2026-09-12
- [CVE-2026-60369](https://intel.threadlinqs.com/cve/CVE-2026-60369) — CVSS 9.9 critical · EPSS 0.4% · published 2026-07-22
- [CVE-2025-40553](https://intel.threadlinqs.com/cve/CVE-2025-40553) — CVSS 9.8 critical · EPSS 14.4% · published 2026-01-28
- [CVE-2024-28988](https://intel.threadlinqs.com/cve/CVE-2024-28988) — CVSS 9.8 critical · EPSS 9.7% · published 2025-09-01
- [CVE-2026-56700](https://intel.threadlinqs.com/cve/CVE-2026-56700) — CVSS 9.8 critical · EPSS 1.6% · published 2026-06-30
- [CVE-2026-58644](https://intel.threadlinqs.com/cve/CVE-2026-58644) — CVSS 9.8 critical · EPSS 1.3% · published 2026-07-14
- [CVE-2026-40860](https://intel.threadlinqs.com/cve/CVE-2026-40860) — CVSS 9.8 critical · EPSS 0.8% · published 2026-04-27
- [CVE-2026-63077](https://intel.threadlinqs.com/cve/CVE-2026-63077) — CVSS 9.8 critical · EPSS 0.6% · published 2026-07-27
- [CVE-2026-60367](https://intel.threadlinqs.com/cve/CVE-2026-60367) — CVSS 9.8 critical · EPSS 0.5% · published 2026-07-22
- [CVE-2026-60372](https://intel.threadlinqs.com/cve/CVE-2026-60372) — CVSS 9.8 critical · EPSS 0.5% · published 2026-07-22
- [CVE-2026-53874](https://intel.threadlinqs.com/cve/CVE-2026-53874) — CVSS 9.8 critical · EPSS 0.5% · published 2026-06-17
- [CVE-2026-18163](https://intel.threadlinqs.com/cve/CVE-2026-18163) — CVSS 9.8 critical · EPSS 0.5% · published 2026-09-22
- [CVE-2026-103040](https://intel.threadlinqs.com/cve/CVE-2026-103040) — CVSS 9.8 critical · published 2026-09-29
- [CVE-2026-103041](https://intel.threadlinqs.com/cve/CVE-2026-103041) — CVSS 9.8 critical · published 2026-09-29
- [CVE-2026-50522](https://intel.threadlinqs.com/cve/CVE-2026-50522) — CVSS 9.8 critical · published 2026-07-14
- [CVE-2026-78265](https://intel.threadlinqs.com/cve/CVE-2026-78265) — CVSS 9.8 critical · published 2026-08-24
- [CVE-2024-28074](https://intel.threadlinqs.com/cve/CVE-2024-28074) — CVSS 9.6 critical · EPSS 0.1% · published 2024-07-17

## Affected vendors

- [Microsoft](https://intel.threadlinqs.com/vendors/microsoft) — 11 CVEs
- [Solarwinds](https://intel.threadlinqs.com/vendors/solarwinds) — 8 CVEs
- **Oracle Corporation** — 6 CVEs
- [Facebook](https://intel.threadlinqs.com/vendors/facebook) — 3 CVEs
- **PTC** — 3 CVEs
- [Vercel](https://intel.threadlinqs.com/vendors/vercel) — 3 CVEs
- [Apache Software Foundation](https://intel.threadlinqs.com/vendors/apache-software-foundation) — 2 CVEs
- **Fortra** — 2 CVEs
- [JetBrains](https://intel.threadlinqs.com/vendors/jetbrains) — 2 CVEs
- **ModelTC** — 2 CVEs
- [picklescan](https://intel.threadlinqs.com/vendors/picklescan) — 2 CVEs
- **Alibaba** — 1 CVE

## Threat activity

164 tracked threats cite CWE-502; the 25 most recent are listed.

- [The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira, REDBIKE, AGENDA)](https://intel.threadlinqs.com/threat/TL-2026-2852) — HIGH · 2026-10-03
- [Warlock Ransomware Attackers Hit Water and Telecom Operators via SharePoint ToolShell Exploitation (Longlegs / Storm-2603)](https://intel.threadlinqs.com/threat/TL-2026-2833) — CRITICAL · 2026-10-01
- [CVE-2019-18935 Telerik UI Deserialization Exploited to Deploy Web Shells and a WordPress Scanner on IIS Servers](https://intel.threadlinqs.com/threat/TL-2026-2726) — CRITICAL · 2026-09-28
- [SolarWinds Access Rights Manager Hard-Coded Cryptographic Key (CVE-2026-28326) Enables Unauthenticated RCE](https://intel.threadlinqs.com/threat/TL-2026-2585) — CRITICAL · 2026-09-19
- [Lazarus Exploits CVE-2026-68820 Zero-Day via Malicious PDF Viewer in Operation Dream Job Against Defense Industry](https://intel.threadlinqs.com/threat/TL-2026-2561) — CRITICAL · 2026-09-18
- [Pro-Ukraine 'Hacking Cat' Group Deploys Gorilla RAT, Monkey Ransomware, and Nemo Wiper Against Russian Targets via Exchange/SharePoint Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2515) — HIGH · 2026-09-15
- [Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker, Qilin, INC Ransom, Lynx) Abuse Dual-Use Tools and Exploit SonicWall, Gladinet CentreStack, and FortiGate Devices](https://intel.threadlinqs.com/threat/TL-2026-2517) — HIGH · 2026-09-15
- [Dell ObjectScale Critical Deserialization Flaw (CVE-2026-70416, CVSS 10.0) Enables Unauthenticated RCE](https://intel.threadlinqs.com/threat/TL-2026-2475) — CRITICAL · 2026-09-13
- [GitLab Patches Max-Severity Unauthenticated Path Traversal Flaw in Repository Commits API (CVE-2026-85706, CVSS 10.0)](https://intel.threadlinqs.com/threat/TL-2026-2442) — CRITICAL · 2026-09-11
- [Ivanti September 2026 Patch Batch: 10 CVEs Across EPMM, Neurons for ITSM, and Sentry (CVE-2026-12744/12745 Unauthenticated Deserialization RCE, CVE-2026-12645-12647 Missing Authorization RCE, CVE-2026-18851 EPMM Privilege Escalation, CVE-2026-83527 Sentry Auth Bypass)](https://intel.threadlinqs.com/threat/TL-2026-2396) — CRITICAL · 2026-09-08
- [September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days (CVE-2026-81963, CVE-2026-85880) and Multiple Critical Wormable RCEs](https://intel.threadlinqs.com/threat/TL-2026-2398) — CRITICAL · 2026-09-08
- [Telerik UI for ASP.NET AJAX — Padding Oracle Chained to Unauthenticated Deserialization RCE (CVE-2026-13181–13184)](https://intel.threadlinqs.com/threat/TL-2026-2369) — HIGH · 2026-09-07
- [StyleSmuggler — Magento Open Source and Adobe Commerce Unauthenticated RCE 0-Day Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2356) — CRITICAL · 2026-09-06
- [StyleSmuggler — Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores](https://intel.threadlinqs.com/threat/TL-2026-2358) — CRITICAL · 2026-09-06
- [DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD Files with Defense Mil-Spec References](https://intel.threadlinqs.com/threat/TL-2026-2364) — CRITICAL · 2026-09-06
- [Pegasus Spyware Used to Hack Phone of Former MEP Stelios Kouloglou, PEGA Committee Member](https://intel.threadlinqs.com/threat/TL-2026-2324) — HIGH · 2026-09-04
- [Chinese-Speaking Operator "Nie" Uses SecFlow AI Orchestration Framework (Claude, Qwen, DeepSeek) and GLUTTON Steganographic Webshell in Multi-Country Espionage Campaign](https://intel.threadlinqs.com/threat/TL-2026-2325) — HIGH · 2026-09-04
- [Recorded Future H1 2026 Report: Actively Exploited CVEs Up 34%, Ransomware Adopts BYOVD and Post-Quantum Crypto](https://intel.threadlinqs.com/threat/TL-2026-2310) — HIGH · 2026-09-03
- [Five Critical WordPress Plugin/Theme Flaws (CVSS up to 10.0) Enable Site Takeover or RCE: WPMU DEV Dashboard, Avada/Fusion Builder, TranslatePress, Pods, GiveWP](https://intel.threadlinqs.com/threat/TL-2026-2210) — CRITICAL · 2026-08-29
- [GiveWP WordPress Donation Plugin Flaw (CVE-2026-82222) Lets Attackers Execute Server Commands](https://intel.threadlinqs.com/threat/TL-2026-2188) — CRITICAL · 2026-08-28
- [FamousSparrow APT Targets Azerbaijani Oil & Gas Sector via ProxyShell/ProxyNotShell Exchange Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2122) — CRITICAL · 2026-08-23
- [2026 Ransomware Surge Targeting US Organizations: Identity-First Compromise, BYOVD, and Living-Off-the-Cloud Exfiltration (Qilin, Akira, Clop, INC Ransom, Play, DragonForce, Sinobi)](https://intel.threadlinqs.com/threat/TL-2026-2125) — HIGH · 2026-08-23
- [CVE-2026-69836: Unauthenticated Remote Code Execution in Microsoft Entra ID via Deserialization of Untrusted Data](https://intel.threadlinqs.com/threat/TL-2026-2107) — CRITICAL · 2026-08-22
- [LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp)](https://intel.threadlinqs.com/threat/TL-2026-2094) — HIGH · 2026-08-21
- [Chinese-speaking threat group UAT-10147 uses agentic AI to automate exploitation of internet-facing web servers](https://intel.threadlinqs.com/threat/TL-2026-2096) — HIGH · 2026-08-21

## Mitigations

- **Architecture and Design, Implementation**: If available, use the signing/sealing features of the programming language to assure that deserialized data has not been tainted. For example, a hash-based message authentication code (HMAC) could be used to ensure that data has not been modified.
- **Implementation**: When deserializing data, populate a new object rather than just deserializing. The result is that the data flows through safe input validation and that the functions are safe.
- **Implementation**: Explicitly define a final object() to prevent deserialization.
- **Architecture and Design, Implementation**: Make fields transient to protect them from deserialization. An attempt to serialize and then deserialize a class containing transient fields will result in NULLs where the transient data should be. This is an excellent way to prevent time, environment-based, or sensitive variables from being carried over and used improperly.
- **Implementation**: Avoid having unnecessary types or gadgets (a sequence of instances and method invocations that can self-execute during the deserialization process, often found in libraries) available that can be leveraged for malicious ends. This limits the potential for unintended or unauthorized types and gadgets to be leveraged by the attacker. Add only acceptable classes to an allowlist. Note: new gadgets are constantly being discovered, so this alone is not a sufficient mitigation.
- **Architecture and Design, Implementation**: Employ cryptography of the data or code for protection. However, it's important to note that it would still be client-side security. This is risky because if the client is compromised then the security implemented on the client (the cryptography) can be bypassed.
- **Operation / Firewall**: Use an application firewall that can detect attacks against this weakness. It can be beneficial in cases in which the code cannot be fixed (because it is controlled by a third party), as an emergency prevention measure while more comprehensive software assurance measures are applied, or to provide defense in depth [REF-1481].

_Source: MITRE CWE, potential mitigations._

## Detection methods (MITRE CWE)

- **Automated Static Analysis** (effectiveness: High): Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

_Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher._

## Related weaknesses

- CWE-913 Improper Control of Dynamically-Managed Code Resources
- CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes

Canonical: https://intel.threadlinqs.com/cwe/CWE-502
Source definition: https://cwe.mitre.org/data/definitions/502.html
Detection rules and IOCs for threats exploiting CWE-502 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
