CVE-2026-4538Disclosure(linuxfoundation / pytorch)

MEDIUMCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch linuxfoundation pytorch systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loading Handler. The manipulation leads to deserialization. The attack can only be performed from a local environment. The exploit is publicly available and might be used. The project was informed of the problem early through a pull request but has not reacted yet.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-502

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pytorch

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 3 classified signals
  • Peaked 1d ago at 5 mentions (2026-03-22); latest day: 1
  • 6 total mentions across 2 days

Affected systems

Products
pytorch

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 2d
01345Mentions · 2026-03-22: 5Mentions · 2026-03-25: 1PoC Mentioned / Linked · 2026-03-25: 1Exploit Tool / Code · 2026-03-25: 1Patch / Workaround · 2026-03-25: 1Technical Details · 2026-03-22: 4Technical Details · 2026-03-25: 103-2203-25
Signal classification2 categories
Disclosure
350.0%
General
350.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-225
Disclosure2General3
2026-03-251
Disclosure1
Full discourse6 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-4538 Local Deserialization Vulnerability in PyTorch 2.10.0 pt2 Loading Handler https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4538

    Post summary

    The entry identifies a local deserialization flaw in PyTorch 2.10.0 but provides no proof‑of‑concept, exploit, or patch information.

    0001036
    4.0K followersView on X
  • RagingCISO@CisoRaging77913
    Disclosure

    CVE-2026-4538: PyTorch 2.10.0—load .pt2 model, get RCE. Researcher submitted fix, PyTorch ignored it. PoC public, unpatched. PickleScan doesn't cover pt2. Data scientists download from HuggingFace like Napster. Your AI pipeline is a malware registry. Unsigned.

    Post summary

    A critical RCE vulnerability in PyTorch 2.10.0 allows arbitrary code execution via .pt2 models; a public PoC exists but the submitted patch was ignored, leaving the issue unpatched.

    00000137
    4 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-4538 📊 Severity: 5.3 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4538 #CVE-2026-4538 #CVE #Medium  #CyberSecurity #InfoSec https://t.co/z5KWF2917n

    Post summary

    The tweet announces a new CVE with basic severity info, but offers no detailed technical data, exploits, or patch information.

    0000018
    111 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4538 A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loading Handler. The manipulation leads to deserializ… https://www.cve.org/CVERecord?id=CVE-2026-4538

    Post summary

    A new vulnerability (CVE-2026-4538) in PyTorch 2.10.0 has been disclosed; details are limited to an unknown function that can manipulate deserialization.

    0000054
    56.8K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4538 - PyTorch pt2 Loading deserialization Intel Report: https://ift.tt/dzuGhtP

    Post summary

    An alert is issued for CVE-2026-4538, a PyTorch deserialization vulnerability, with a linked Intel report, but no evidence of exploitation, PoC, or mitigation details.

    0000016
    291 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4538 - PyTorch pt2 Loading deserialization Intel Report: https://ift.tt/CUlHdAm

    Post summary

    An alert cites CVE-2026-4538 impacting PyTorch deserialization, but no PoC, exploit, active exploitation, patch, or false‑positive claim is provided.

    0000017
    291 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxfoundationpytorch2.10.0python-

Explore more