On this page
CWE-502: Deserialization of Untrusted Data
Weakness Summary
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
- Canonical source: MITRE CWE-502 (opens in a new tab)
- Published Atomicorp CVE observations: 48
- Distinct affected products in those observations: 41
- Active Atomicorp rules associated with this weakness: 44
Atomicorp Research Context
Atomicorp has published CVE-specific research observations associated with this weakness category. Each linked CVE page states whether the tested request was detected or blocked and is the authoritative customer-facing finding.
The CVEs and rules shown here are selected published examples, not a complete list of Atomicorp protections. If a CWE, CVE, or rule is absent from this page, no conclusion should be drawn about whether Atomicorp protects against that weakness or attack method.
A CWE describes a class of software weakness. It does not identify one exploit request, and association with a CWE does not mean that every vulnerability or exploitation path in that category is detected or blocked.
Selected Published CVE Observations
| CVE | Vulnerability | Product | Atomicorp finding | Observed rules |
|---|---|---|---|---|
| CVE-2021-44228 | Apache Log4j2 Remote Code Injection | log4j | Attack Blocked by Atomicorp | 345115 , 345117 , 345118 , 393655 |
| CVE-2025-55182 | React Server Components - Remote Code Execution | react | Attack Blocked by Atomicorp | 331702 , 344370 , 345240 , 380026 , 393655 |
| CVE-2021-21345 | XStream < 1.4.16 - Remote Code Execution | xstream | Attack Blocked by Atomicorp | 344363 , 344366 |
| CVE-2026-34838 | Group-Office: Authenticated Remote Code Execution via PHP Insecure Deserialization in AbstractSettingsCollection | group-office | Attack Blocked by Atomicorp | 340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390613 , 390614 , 390722 , 398008 |
| CVE-2015-7501 | Red Hat JBoss - Insecure Deserialization | jboss enterprise application platform | Attack Blocked by Atomicorp | 344380 |
| CVE-2017-17672 | vBulletin 5.x - 'cacheTemplates' Remote Arbitrary File Deletion | vbulletin | Attack Blocked by Atomicorp | 344370 , 390614 |
| CVE-2018-1000861 | Jenkins - Remote Command Injection | jenkins | Attack Blocked by Atomicorp | 344370 , 390722 |
| CVE-2018-19276 | OpenMRS Platform < 2.24.0 - Insecure Object Deserialization | openmrs | Attack Blocked by Atomicorp | 330791 , 340152 , 344361 , 344363 , 344364 , 344366 , 344370 |
| CVE-2019-10068 | Kentico CMS Insecure Deserialization Remote Code Execution | kentico | Attack Blocked by Atomicorp | 341256 |
| CVE-2019-17564 | Apache Dubbo 2.5.x-2.7.4 - Insecure Deserialization | dubbo | Attack Blocked by Atomicorp | 344370 , 344380 , 390614 , 390626 , 390724 |
| CVE-2019-5434 | Revive Adserver 4.2 - Remote Code Execution | revive adserver | Attack Blocked by Atomicorp | 344362 , 344365 , 344370 |
| CVE-2020-10189 | ManageEngine Desktop Central Java Deserialization | manageengine desktop central | Attack Blocked by Atomicorp | 340007 , 344365 , 344380 , 347019 |
| CVE-2020-29047 | WP Hotel Booking < 1.10.4 - PHP Object Injection | wp hotel booking | Attack Blocked by Atomicorp | 330889 |
| CVE-2020-9547 | FasterXML jackson-databind - Deserialization Remote Code Execution | jackson-databind | Detected by Atomicorp | 398008 |
| CVE-2020-9548 | FasterXML Jackson Databind <=2.9.10.4 - Remote Code Execution | jackson-databind | Detected by Atomicorp | 398008 |
| CVE-2021-42237 | Sitecore Experience Platform Pre-Auth RCE | experience platform | Attack Blocked by Atomicorp | 344362 , 344366 |
| CVE-2022-35405 | Zoho ManageEngine - Remote Code Execution | manageengine access manager plus | Attack Blocked by Atomicorp | 392301 |
| CVE-2022-47986 | IBM Aspera Faspex <=4.4.2 PL1 - Remote Code Execution | linux kernel | Attack Blocked by Atomicorp | 344364 , 344370 |
| CVE-2023-25135 | vBulletin <= 5.6.9 - Pre-authentication Remote Code Execution | vbulletin | Attack Blocked by Atomicorp | 344365 , 390614 |
| CVE-2023-29300 | Adobe ColdFusion - Pre-Auth Remote Code Execution | coldfusion | Attack Blocked by Atomicorp | 344370 , 344380 , 350147 |
| CVE-2023-38203 | Adobe ColdFusion - Deserialization of Untrusted Data | coldfusion | Attack Blocked by Atomicorp | 344370 , 344380 , 350147 |
| CVE-2023-43208 | NextGen Healthcare Mirth Connect - Remote Code Execution | mirth connect | Attack Blocked by Atomicorp | 344363 , 344364 , 344380 |
| CVE-2023-44353 | Adobe ColdFusion WDDX Deserialization Gadgets | coldfusion | Attack Blocked by Atomicorp | 344365 , 344370 , 350147 |
| CVE-2023-47248 | PyArrow Flight RPC - Remote Code Execution | pyarrow | Attack Blocked by Atomicorp | 391213 |
| CVE-2024-5932 | GiveWP - PHP Object Injection | givewp | Detected by Atomicorp | 398001 |
| CVE-2024-8353 | GiveWP Donation Plugin <= 3.16.1 - Unauthenticated PHP Object Injection | givewp | Attack Blocked by Atomicorp | 340014 , 344370 |
| CVE-2025-24813 | Apache Tomcat Path Equivalence - Remote Code Execution | tomcat | Attack Blocked by Atomicorp | 392301 |
| CVE-2025-53770 | Microsoft SharePoint Server - Remote Code Execution (ToolShell) | sharepoint server | Attack Blocked by Atomicorp | 330906 , 350147 |
| CVE-2025-59287 | Windows Server Update Service - Insecure Deserialization | Windows Server update service | Attack Blocked by Atomicorp | 392647 |
| CVE-2026-3296 | Everest Forms <= 3.4.3 - Unauthenticated PHP Object Injection via Form Entry Metadata | Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder | Attack Blocked by Atomicorp | 300007 , 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 |
| CVE-2025-25034 | SugarCRM - Unauthenticated Remote Code Execution via PHP Object Injection | SugarCRM | Attack Blocked by Atomicorp | 344370 |
| CVE-2026-10042 | manga-image-translator RCE via Unsafe Pickle Deserialization in Share Model | manga-image-translator | Attack Blocked by Atomicorp | 340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390613 , 390614 , 390722 , 398008 |
| CVE-2026-27971 | Qwik - Unauthenticated RCE via server$ Deserialization | qwik | Attack Blocked by Atomicorp | 391213 |
| CVE-2026-46725 | TYPO3 ceselector Extension - Insecure Deserialization | ceselector | Attack Blocked by Atomicorp | 360153 |
| CVE-2026-87930 | MaxSite CMS through 109.6 PHP Object Injection via ci_session | MaxSite CMS | Attack Blocked by Atomicorp | 340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390613 , 390614 , 390722 |
| CVE-2021-21351 | XStream <1.4.16 - Remote Code Execution | xstream | Attack Blocked by Atomicorp | 344380 |
| CVE-2025-5086 | Dassault Systèmes DELMIA Apriso (up to 2025) - Insecure Deserialization | delmia apriso | Attack Blocked by Atomicorp | 331702 , 344380 |
| CVE-2025-71260 | BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 VIEWSTATE Deserialization RCE | footprints | Attack Blocked by Atomicorp | 340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344382 , 344385 , 390613 , 390614 , 390722 , 398008 |
| CVE-2026-71981 | Cypht < 2.12.2 PHP Object Injection RCE via back_query Parameter | cypht | Attack Blocked by Atomicorp | 340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390613 , 390614 , 390722 , 398008 |
| CVE-2021-39144 | XStream 1.4.18 - Remote Code Execution | xstream | Attack Blocked by Atomicorp | 344363 |
| CVE-2017-9805 | Apache Struts2 S2-052 - Remote Code Execution | struts | Attack Blocked by Atomicorp | 344360 , 344364 , 344366 |
| CVE-2019-6340 | Drupal - Remote Code Execution | drupal | Attack Blocked by Atomicorp | 392301 |
| CVE-2026-12720 | Kirki < 6.0.13 - Unauthenticated PHP Object Injection | Kirki | Attack Blocked by Atomicorp | 340014 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390614 , 398008 |
| CVE-2026-61686 | SolidInvoice: PHP unserialize() called on client-controlled data in DataGrid LiveComponent context prop | SolidInvoice | Attack Blocked by Atomicorp | 340014 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390614 , 398008 |
| CVE-2023-0669 | Fortra GoAnywhere MFT - Remote Code Execution | goanywhere managed file transfer | Attack Blocked by Atomicorp | 344370 |
| CVE-2026-16297 | Clearfy < 2.4.3 - Admin+ PHP Object Injection via Settings Import | Clearfy Cache | Attack Blocked by Atomicorp | 340014 , 340023 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390904 , 398008 |
| CVE-2023-3360 | Weaver Show Posts < 1.8.1 - Admin+ PHP Object Injection | Weaver Show Posts | Attack Blocked by Atomicorp | 340014 , 340023 , 344362 , 344363 , 344370 , 344380 , 344382 , 344385 , 390614 , 398008 |
| CVE-2025-8266 | ChanCMS <= 3.1. - Remote Code Execution | chancms | Attack Blocked by Atomicorp | 345240 , 380026 |
Associated Atomicorp WAF Rules
| Rule | Status | Behavior |
|---|---|---|
| 300007 | Active | disruptive (deny) |
| 330791 | Active | disruptive (deny) |
| 330889 | Active | disruptive (deny) |
| 330906 | Active | disruptive (deny) |
| 331702 | Active | disruptive (deny) |
| 340007 | Active | disruptive (deny) |
| 340014 | Active | disruptive (deny) |
| 340023 | Active | disruptive (deny) |
| 340029 | Active | disruptive (deny) |
| 340152 | Active | disruptive (deny) |
| 340193 | Active | disruptive (deny) |
| 341256 | Active | disruptive (deny) |
| 344360 | Active | disruptive (deny) |
| 344361 | Active | disruptive (deny) |
| 344362 | Active | disruptive (deny) |
| 344363 | Active | disruptive (deny) |
| 344364 | Active | disruptive (deny) |
| 344365 | Active | disruptive (deny) |
| 344366 | Active | disruptive (deny) |
| 344370 | Active | disruptive (deny) |
| 344380 | Active | disruptive (deny) |
| 344382 | Active | disruptive (deny) |
| 344385 | Active | disruptive (deny) |
| 345115 | Active | disruptive (deny) |
| 345117 | Active | disruptive (deny) |
| 345118 | Active | disruptive (deny) |
| 345240 | Active | disruptive (deny) |
| 347009 | Active | disruptive (deny) |
| 347019 | Active | disruptive (deny) |
| 350147 | Active | disruptive (deny) |
| 360153 | Active | disruptive (deny) |
| 380026 | Active | disruptive (deny) |
| 390613 | Active | disruptive (deny) |
| 390614 | Active | disruptive (deny) |
| 390626 | Active | disruptive (deny) |
| 390722 | Active | disruptive (deny) |
| 390724 | Active | disruptive (deny) |
| 390904 | Active | disruptive (deny) |
| 391213 | Active | disruptive (deny) |
| 392301 | Active | disruptive (deny) |
| 392647 | Active | disruptive (deny) |
| 393655 | Active | disruptive (deny) |
| 398001 | Active | non-disruptive (pass) |
| 398008 | Active | non-disruptive (pass) |
Related MITRE CAPEC Context
MITRE associates this CWE with the following attack-pattern entries. These taxonomy relationships are context, not Atomicorp coverage claims: