CVE-2026-11756
🟠 Łataj w tym tygodniu
Deserializacja niezaufanych danych w aplikacji Station Launcher umożliwia zdalne wykonanie kodu.
CVSS
10.0
EPSS
0.4%
Exploit
none
Vendor
Opis źródłowy (NVD)
A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthenticated remote code execution.
deserialization rce
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 10.0 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.4% |
| Opublikowano (NVD) | 2026-07-28 08:17:14 UTC |
| Ostatnia modyfikacja (NVD) | 2026-07-30 19:11:32 UTC |
Referencje
- https://www.3ds.com/trust-center/security/security-advisories/cve-2026-11756 (3DS.Information-Security@3ds.com)