CVE-2026-26210Disclosure(kvcache-ai / ktransformers)

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (4 latest mentions)

Immediate actions

  • Patch kvcache-ai ktransformers systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

KTransformers through 0.5.3 contains an unsafe deserialization vulnerability in the balance_serve backend mode where the scheduler RPC server binds a ZMQ ROUTER socket to all interfaces with no authentication and deserializes incoming messages using pickle.loads() without validation. Attackers can send a crafted pickle payload to the exposed ZMQ socket to execute arbitrary code on the server with the privileges of the ktransformers process.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ktransformers

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-05-11)
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
ktransformers

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-04-23: 1Mentions · 2026-05-11: 4PoC Mentioned / Linked · 2026-04-23: 1Patch / Workaround · 2026-04-23: 1Technical Details · 2026-04-23: 1Technical Details · 2026-05-11: 304-2305-11
Signal classification3 categories
Disclosure
240.0%
General
240.0%
PoC
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-231
PoC1
2026-05-114
Disclosure2General2
Full discourse5 posts
  • Chocapikk@Chocapikk_
    PoC

    New writeups: CVE-2026-25874 - HuggingFace LeRobot (21.5k stars) - Unauthenticated RCE via pickle deserialization in gRPC PolicyServer. CVSS 9.3. https://chocapikk.com/posts/2026/lerobot-pickle-rce/ CVE-2026-26210 - KTransformers (16.5k stars) - Unauthenticated RCE via pickle deserialization in ZMQ scheduler. CVSS 9.8. Fix PR submitted. https://chocapikk.com/posts/2026/ktransformers-pickle-rce/ As always, thanks to @VulnCheckAI for the CVE coordination.

    Post summary

    New writeups reveal that CVE-2026-25874 and CVE-2026-26210 involve unauthenticated RCE via pickle deserialization with high CVSS scores, and patches are underway.

    214146194.5K
    4.0K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVE: CVE-2026-26210 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory CRITICAL: CVE-2026-26210 (CVSS 9.8) — kvcache-ai ktransformers

    Post summary

    The text announces CVE-2026-26210 as a critical vulnerability with a CVSS score of 9.8, but it lacks further details on exploitation, patches, or mitigation.

    0000030
    188 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-26210-kvcache-ai-ktransformers #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The text shares a link and hashtags but offers no concrete information about the CVE, its exploitation, or remediation.

    0000011
    188 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-26210 (CVSS 9.8) — kvcache-ai ktransformers KTransformers through 0.5.3 contains an unsafe deserialization vulnerability in the balanceserve backend mode where the scheduler RPC server binds a ZMQ ROUTER socket to all interfaces with no authentication…

    Post summary

    A newly disclosed CVE‑2026‑26210 exposes a critical unsafe deserialization flaw in KTransformers 0.5.3, with a CVSS score of 9.8, but no PoC, exploit, patch, or active exploitation status is mentioned.

    0000031
    197 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVSS 9.8 CRITICAL · CVE-2026-26210 · 9.8 → 0.5.3 CRITICAL: CVE-2026-26210 (CVSS 9.8) — kvcache-ai ktransformers

    Post summary

    The text simply announces CVE-2026-26210 with its CVSS score of 9.8, without providing further context such as exploits, patches, or active usage.

    0000032
    197 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkvcache-aiktransformers---

Explore more