On this page

CWE-502: Deserialization of Untrusted Data

Weakness Summary

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

  • Canonical source: MITRE CWE-502 (opens in a new tab)
  • Published Atomicorp CVE observations: 48
  • Distinct affected products in those observations: 41
  • Active Atomicorp rules associated with this weakness: 44

Atomicorp Research Context

Atomicorp has published CVE-specific research observations associated with this weakness category. Each linked CVE page states whether the tested request was detected or blocked and is the authoritative customer-facing finding.

The CVEs and rules shown here are selected published examples, not a complete list of Atomicorp protections. If a CWE, CVE, or rule is absent from this page, no conclusion should be drawn about whether Atomicorp protects against that weakness or attack method.

A CWE describes a class of software weakness. It does not identify one exploit request, and association with a CWE does not mean that every vulnerability or exploitation path in that category is detected or blocked.

Selected Published CVE Observations

CVEVulnerabilityProductAtomicorp findingObserved rules
CVE-2021-44228Apache Log4j2 Remote Code Injectionlog4jAttack Blocked by Atomicorp345115 , 345117 , 345118 , 393655
CVE-2025-55182React Server Components - Remote Code ExecutionreactAttack Blocked by Atomicorp331702 , 344370 , 345240 , 380026 , 393655
CVE-2021-21345XStream < 1.4.16 - Remote Code ExecutionxstreamAttack Blocked by Atomicorp344363 , 344366
CVE-2026-34838Group-Office: Authenticated Remote Code Execution via PHP Insecure Deserialization in AbstractSettingsCollectiongroup-officeAttack Blocked by Atomicorp340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390613 , 390614 , 390722 , 398008
CVE-2015-7501Red Hat JBoss - Insecure Deserializationjboss enterprise application platformAttack Blocked by Atomicorp344380
CVE-2017-17672vBulletin 5.x - 'cacheTemplates' Remote Arbitrary File DeletionvbulletinAttack Blocked by Atomicorp344370 , 390614
CVE-2018-1000861Jenkins - Remote Command InjectionjenkinsAttack Blocked by Atomicorp344370 , 390722
CVE-2018-19276OpenMRS Platform < 2.24.0 - Insecure Object DeserializationopenmrsAttack Blocked by Atomicorp330791 , 340152 , 344361 , 344363 , 344364 , 344366 , 344370
CVE-2019-10068Kentico CMS Insecure Deserialization Remote Code ExecutionkenticoAttack Blocked by Atomicorp341256
CVE-2019-17564Apache Dubbo 2.5.x-2.7.4 - Insecure DeserializationdubboAttack Blocked by Atomicorp344370 , 344380 , 390614 , 390626 , 390724
CVE-2019-5434Revive Adserver 4.2 - Remote Code Executionrevive adserverAttack Blocked by Atomicorp344362 , 344365 , 344370
CVE-2020-10189ManageEngine Desktop Central Java Deserializationmanageengine desktop centralAttack Blocked by Atomicorp340007 , 344365 , 344380 , 347019
CVE-2020-29047WP Hotel Booking < 1.10.4 - PHP Object Injectionwp hotel bookingAttack Blocked by Atomicorp330889
CVE-2020-9547FasterXML jackson-databind - Deserialization Remote Code Executionjackson-databindDetected by Atomicorp398008
CVE-2020-9548FasterXML Jackson Databind <=2.9.10.4 - Remote Code Executionjackson-databindDetected by Atomicorp398008
CVE-2021-42237Sitecore Experience Platform Pre-Auth RCEexperience platformAttack Blocked by Atomicorp344362 , 344366
CVE-2022-35405Zoho ManageEngine - Remote Code Executionmanageengine access manager plusAttack Blocked by Atomicorp392301
CVE-2022-47986IBM Aspera Faspex <=4.4.2 PL1 - Remote Code Executionlinux kernelAttack Blocked by Atomicorp344364 , 344370
CVE-2023-25135vBulletin <= 5.6.9 - Pre-authentication Remote Code ExecutionvbulletinAttack Blocked by Atomicorp344365 , 390614
CVE-2023-29300Adobe ColdFusion - Pre-Auth Remote Code ExecutioncoldfusionAttack Blocked by Atomicorp344370 , 344380 , 350147
CVE-2023-38203Adobe ColdFusion - Deserialization of Untrusted DatacoldfusionAttack Blocked by Atomicorp344370 , 344380 , 350147
CVE-2023-43208NextGen Healthcare Mirth Connect - Remote Code Executionmirth connectAttack Blocked by Atomicorp344363 , 344364 , 344380
CVE-2023-44353Adobe ColdFusion WDDX Deserialization GadgetscoldfusionAttack Blocked by Atomicorp344365 , 344370 , 350147
CVE-2023-47248PyArrow Flight RPC - Remote Code ExecutionpyarrowAttack Blocked by Atomicorp391213
CVE-2024-5932GiveWP - PHP Object InjectiongivewpDetected by Atomicorp398001
CVE-2024-8353GiveWP Donation Plugin <= 3.16.1 - Unauthenticated PHP Object InjectiongivewpAttack Blocked by Atomicorp340014 , 344370
CVE-2025-24813Apache Tomcat Path Equivalence - Remote Code ExecutiontomcatAttack Blocked by Atomicorp392301
CVE-2025-53770Microsoft SharePoint Server - Remote Code Execution (ToolShell)sharepoint serverAttack Blocked by Atomicorp330906 , 350147
CVE-2025-59287Windows Server Update Service - Insecure DeserializationWindows Server update serviceAttack Blocked by Atomicorp392647
CVE-2026-3296Everest Forms <= 3.4.3 - Unauthenticated PHP Object Injection via Form Entry MetadataEverest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form BuilderAttack Blocked by Atomicorp300007 , 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009
CVE-2025-25034SugarCRM - Unauthenticated Remote Code Execution via PHP Object InjectionSugarCRMAttack Blocked by Atomicorp344370
CVE-2026-10042manga-image-translator RCE via Unsafe Pickle Deserialization in Share Modelmanga-image-translatorAttack Blocked by Atomicorp340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390613 , 390614 , 390722 , 398008
CVE-2026-27971Qwik - Unauthenticated RCE via server$ DeserializationqwikAttack Blocked by Atomicorp391213
CVE-2026-46725TYPO3 ceselector Extension - Insecure DeserializationceselectorAttack Blocked by Atomicorp360153
CVE-2026-87930MaxSite CMS through 109.6 PHP Object Injection via ci_sessionMaxSite CMSAttack Blocked by Atomicorp340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390613 , 390614 , 390722
CVE-2021-21351XStream <1.4.16 - Remote Code ExecutionxstreamAttack Blocked by Atomicorp344380
CVE-2025-5086Dassault Systèmes DELMIA Apriso (up to 2025) - Insecure Deserializationdelmia aprisoAttack Blocked by Atomicorp331702 , 344380
CVE-2025-71260BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 VIEWSTATE Deserialization RCEfootprintsAttack Blocked by Atomicorp340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344382 , 344385 , 390613 , 390614 , 390722 , 398008
CVE-2026-71981Cypht < 2.12.2 PHP Object Injection RCE via back_query ParametercyphtAttack Blocked by Atomicorp340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390613 , 390614 , 390722 , 398008
CVE-2021-39144XStream 1.4.18 - Remote Code ExecutionxstreamAttack Blocked by Atomicorp344363
CVE-2017-9805Apache Struts2 S2-052 - Remote Code ExecutionstrutsAttack Blocked by Atomicorp344360 , 344364 , 344366
CVE-2019-6340Drupal - Remote Code ExecutiondrupalAttack Blocked by Atomicorp392301
CVE-2026-12720Kirki < 6.0.13 - Unauthenticated PHP Object InjectionKirkiAttack Blocked by Atomicorp340014 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390614 , 398008
CVE-2026-61686SolidInvoice: PHP unserialize() called on client-controlled data in DataGrid LiveComponent context propSolidInvoiceAttack Blocked by Atomicorp340014 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390614 , 398008
CVE-2023-0669Fortra GoAnywhere MFT - Remote Code Executiongoanywhere managed file transferAttack Blocked by Atomicorp344370
CVE-2026-16297Clearfy < 2.4.3 - Admin+ PHP Object Injection via Settings ImportClearfy CacheAttack Blocked by Atomicorp340014 , 340023 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390904 , 398008
CVE-2023-3360Weaver Show Posts < 1.8.1 - Admin+ PHP Object InjectionWeaver Show PostsAttack Blocked by Atomicorp340014 , 340023 , 344362 , 344363 , 344370 , 344380 , 344382 , 344385 , 390614 , 398008
CVE-2025-8266ChanCMS <= 3.1. - Remote Code ExecutionchancmsAttack Blocked by Atomicorp345240 , 380026

Associated Atomicorp WAF Rules

RuleStatusBehavior
300007Activedisruptive (deny)
330791Activedisruptive (deny)
330889Activedisruptive (deny)
330906Activedisruptive (deny)
331702Activedisruptive (deny)
340007Activedisruptive (deny)
340014Activedisruptive (deny)
340023Activedisruptive (deny)
340029Activedisruptive (deny)
340152Activedisruptive (deny)
340193Activedisruptive (deny)
341256Activedisruptive (deny)
344360Activedisruptive (deny)
344361Activedisruptive (deny)
344362Activedisruptive (deny)
344363Activedisruptive (deny)
344364Activedisruptive (deny)
344365Activedisruptive (deny)
344366Activedisruptive (deny)
344370Activedisruptive (deny)
344380Activedisruptive (deny)
344382Activedisruptive (deny)
344385Activedisruptive (deny)
345115Activedisruptive (deny)
345117Activedisruptive (deny)
345118Activedisruptive (deny)
345240Activedisruptive (deny)
347009Activedisruptive (deny)
347019Activedisruptive (deny)
350147Activedisruptive (deny)
360153Activedisruptive (deny)
380026Activedisruptive (deny)
390613Activedisruptive (deny)
390614Activedisruptive (deny)
390626Activedisruptive (deny)
390722Activedisruptive (deny)
390724Activedisruptive (deny)
390904Activedisruptive (deny)
391213Activedisruptive (deny)
392301Activedisruptive (deny)
392647Activedisruptive (deny)
393655Activedisruptive (deny)
398001Activenon-disruptive (pass)
398008Activenon-disruptive (pass)

MITRE associates this CWE with the following attack-pattern entries. These taxonomy relationships are context, not Atomicorp coverage claims:

CAPEC-586 (opens in a new tab)