CVE-2026-48207Disclosure(apache / fory)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apache fory systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented DeserializationPolicy validation hooks during reduce-state restoration and global-name resolution. An application is vulnerable if it deserializes attacker-controlled data using PyFory Python-native mode with strict mode disabled and relies on DeserializationPolicy to restrict unsafe classes, functions, or module attributes. This issue affects Apache Fory: from before 1.0.0. Mitigation: Users of Apache Fory are recommended to upgrade to version 1.0.0 or later, which enforces DeserializationPolicy validation for the affected ReduceSerializer paths and thus fixes this issue.

2.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fory

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 7d ago at 1 mentions (2026-05-22); latest day: 1
  • 8 total mentions across 8 days

Affected systems

Vendors
Products
fory

Deep dive

Activity timeline8 mentions / 8d
00111Mentions · 2026-05-22: 1Mentions · 2026-05-23: 1Mentions · 2026-05-27: 1Mentions · 2026-06-05: 1Mentions · 2026-06-07: 1Mentions · 2026-06-08: 1Mentions · 2026-06-09: 1Mentions · 2026-06-12: 1PoC Mentioned / Linked · 2026-06-12: 1Patch / Workaround · 2026-05-22: 1Patch / Workaround · 2026-05-27: 1Technical Details · 2026-05-22: 1Technical Details · 2026-05-23: 1Technical Details · 2026-05-27: 1Technical Details · 2026-06-12: 105-2205-2305-2706-0506-0706-0806-0906-12
Signal classification3 categories
Disclosure
562.5%
Patch
225.0%
General
112.5%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-221
Patch1
2026-05-231
Disclosure1
2026-05-271
Patch1
2026-06-051
Disclosure1
2026-06-071
Disclosure1
2026-06-081
Disclosure1
2026-06-091
General1
2026-06-121
Disclosure1
Full discourse8 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-48207: Apache Fory: PyFory ReduceSerializer Incomplete Policy Enforcement https://www.openwall.com/lists/oss-security/2026/05/21/10 Severity: important Deserialization of untrusted data. Bypass documented DeserializationPolicy validation hooks during reduce-state restoration and global-name resolution.

    Post summary

    A new CVE (CVE‑2026‑48207) affecting Apache PyFory’s ReduceSerializer component is disclosed, detailing a deserialization-based policy bypass that could enable execution of untrusted data during state restoration.

    010301.1K
    4.7K followersView on X
  • EcuCERT@EcuCERT_EC
    Disclosure

    La vulnerabilidad CVE-2026-48207 en Apache Fory (PyFory) permite eludir controles de deserialización y provocar RCE o DoS. Mas información: https://www.ecucert.gob.ec/wp-content/uploads/2026/06/Al-2026-031-CVE-2026-48207-%E2%80%93-Bypass-de-Politicas-de-Deserializacion-en-Apache-Fory-PyFory.pdf #PorUnEcuadorCiberseguro @Arcotel_ec @CsirtCEDIA @CsirtEPN https://t.co/S9wvFOwX33

    Post summary

    The post announces CVE-2026-48207 affecting Apache Fory (PyFory), describing a deserialization-bypass that permits RCE or DoS, and points to a PDF with additional details.

    0100093
    2.0K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Discover how CVE-2026-48207, a critical PyFory deserialization policy bypass flaw, lets attackers execute remote code, and learn how to patch it now. #ApacheFory #PyFory #VulnerabilityPatch #RCE #AppSec https://securityonline.info/pyfory-deserialization-policy-bypass/ https://t.co/QELb4Uo9yk

    Post summary

    The tweet announces the discovery of a critical PyFory deserialization flaw (CVE-2026-48207) that allows remote code execution and directs readers to patch guidance.

    00010305
    12.2K followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    General

    【緊急】CVE-2026-48207 Apache Foryに深刻な脆弱性|即時対応が必要 https://www.cybernote.click/2026/06/05/cve-2026-48207-apache-fory/ #IT #Security #cybersecurity

    Post summary

    The post alerts that CVE-2026-48207 in Apache Fory is serious and requires immediate response, but offers no further details or actionable information.

    0000044
    209 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Disclosure

    【緊急】CVE-2026-48207 Apache Foryに深刻な脆弱性|即時対応が必要 https://www.cybernote.click/2026/06/05/cve-2026-48207-apache-fory/ #IT #Security #cybersecurity

    Post summary

    An urgent advisory announces a serious vulnerability in Apache Fory, urging immediate action, but provides no technical or remedial details.

    0000060
    209 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Disclosure

    【緊急】CVE-2026-48207 Apache Foryに深刻な脆弱性|即時対応が必要 https://www.cybernote.click/2026/06/05/cve-2026-48207-apache-fory/ #IT #Security #cybersecurity

    Post summary

    A notice warns of a serious vulnerability in Apache Fory (CVE-2026-48207) and urges immediate action, but no technical details, exploit code, or patch information are included.

    0000029
    209 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Disclosure

    【緊急】CVE-2026-48207 Apache Foryに深刻な脆弱性|即時対応が必要 https://www.cybernote.click/2026/06/05/cve-2026-48207-apache-fory/ #IT #Security #cybersecurity

    Post summary

    The post announces a new critical vulnerability CVE‑2026‑48207 in Apache Fory and urges immediate action.

    0000037
    209 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 CRITICAL CVE-2026-48207 | CVSS 9.8 Apache Fory PyFory deserialization flaw allows attackers to bypass DeserializationPolicy validation. Affects versions before 1.0.0. ✅ Upgrade to v1.0.0+ immediately #CVE #Vulnerability #PatchNow https://t.co/z3qS2QtzCn

    Post summary

    The tweet announces a critical CVE-2026-48207 with a deserialization flaw, recommends immediate patching to version 1.0.0+, and includes CVSS details.

    0000051
    30 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachefory---

Explore more