CVE-2026-3060Disclosure(lmsys / sglang)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch lmsys sglang systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

SGLang' encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sglang

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 6 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 5d ago at 1 mentions (2026-03-12); latest day: 1
  • 6 total mentions across 6 days

Affected systems

Vendors
Products
sglang

Deep dive

Activity timeline6 mentions / 6d
00111Mentions · 2026-03-12: 1Mentions · 2026-03-13: 1Mentions · 2026-03-16: 1Mentions · 2026-04-09: 1Mentions · 2026-04-16: 1Mentions · 2026-04-20: 1Active Exploitation · 2026-04-20: 1Patch / Workaround · 2026-04-09: 1Technical Details · 2026-03-12: 1Technical Details · 2026-03-13: 1Technical Details · 2026-03-16: 1Technical Details · 2026-04-09: 1Technical Details · 2026-04-16: 1Technical Details · 2026-04-20: 103-1203-1303-1604-0904-1604-20
Signal classification3 categories
Disclosure
466.7%
General
116.7%
Active Exploitation
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-121
Disclosure1
2026-03-131
Disclosure1
2026-03-161
Disclosure1
2026-04-091
Disclosure1
2026-04-161
General1
2026-04-201
Active Exploitation1
Full discourse6 posts
  • Gray Hats@the_yellow_fall
    Disclosure

    Critical 9.8 CVSS unpatched RCE flaws in the SGLang AI framework (CVE-2026-3059 & CVE-2026-3060) expose servers via unsafe Python pickle deserialization. #SGLang #AISecurity #PickleDeserialization #CVE #LLMSecurity #CyberSecurity #InfoSec #RCE #ZeroDay https://securityonline.info/poisoned-pickle-critical-unpatched-rce-flaws-sglang-ai-infrastructure/ https://t.co/ZAln4BRyXc

    Post summary

    The tweet announces a critical RCE vulnerability in the SGLang AI framework, describing technical details such as a 9.8 CVSS score and unsafe pickle deserialization, but provides no proof‑of‑concept, exploit code, or information on patching or active exploitation.

    02041456
    10.7K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploiting CVE-2026-3060 in SGLang to achieve unauthenticated RCE through malicious GGUF model files. Once compromised, lateral movement within AI infrastructure networks becomes a critical concern. Runtime segmentation helps contain post-compromise activity across model serving environments. #ZeroDay #CloudSecurity 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/sglang-cve-2026-5760-rce-via-malicious-gguf-model-files

    Post summary

    The tweet reports that attackers are actively exploiting CVE-2026-3060 to gain unauthenticated remote code execution through malicious GGUF model files.

    0000035
    1.9K followersView on X
  • O Pantera Negra · IA & Produto 🤖@opanteranegra77
    General

    Detalhe: ZMQ broker deserializa dados untrusted; CVE-2026-3060 = disaggregation encoder RCE. Ambos não precisam de credencial. Rodei SGLang 0.2.x em 2 setups (H100, L40S). Resultado: não é "baixa severidade", é "critical".

    Post summary

    The post explains that CVE-2026-3060 is a remote code execution vulnerability in the ZMQ broker’s disaggregation encoder, clarifies that the flaw requires no credentials, and asserts its severity is critical.

    0000033
    232 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    An unauthenticated RCE vulnerability (CVE-2026-3060) affects `SGLang`'s disaggregation system, allowing arbitrary code execution. Restrict network access. #SGLang #RCE #infosec https://www.pulsepatch.io/posts/cve-2026-3060-sg-lang-remote-code-execution

    Post summary

    The post announces an unauthenticated remote‑code‑execution vulnerability (CVE‑2026‑3060) in SGLang’s disaggregation system and recommends restricting network access as a mitigation.

    0000046
    11 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3060 SGLang' encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted da… https://www.cve.org/CVERecord?id=CVE-2026-3060

    Post summary

    The text announces CVE‑2026‑3060, a remote code execution flaw in SGLang’s encoder parallel disaggregation system caused by deserializing untrusted data, and provides a brief technical description but no PoC, exploit, patch, or evidence of active use.

    00000176
    56.7K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-3060 - Critical SGLang' encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.load... https://www.thehackerwire.com/vulnerability/CVE-2026-3060/ https://t.co/YkK0PwohWM

    Post summary

    CVE-2026-3060 is a critical remote‑code‑execution flaw in SGLang’s encoder parallel disaggregation system that deserializes untrusted data with pickle.load. The post provides technical details but no PoC, exploit code, patch, or evidence of active exploitation.

    0000048
    134 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applmsyssglang---

Explore more