CVE-2026-4860Disclosure

LOWCVSS 5.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security flaw has been discovered in 648540858 wvp-GB28181-pro up to 2.7.4. This affects the function GenericFastJsonRedisSerializer of the file src/main/java/com/genersoft/iot/vmp/conf/redis/RedisTemplateConfig.java of the component API Endpoint. The manipulation results in deserialization. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-26: 2Technical Details · 2026-03-26: 203-26
Signal classification1 categories
Disclosure
2100.0%
Referenced assets3 URLs
Full discourse2 posts
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4860 - 648540858 wvp-GB28181-pro API Endpoint http://RedisTemplateConfig.java GenericFastJsonRedisSerializer deserialization Intel Report: https://ift.tt/2ImPX3y

    Post summary

    The alert announces CVE-2026-4860, pointing out a vulnerable API endpoint that uses GenericFastJsonRedisSerializer deserialization, and links to an Intel report for further information.

    1001028
    286 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4860 A security flaw has been discovered in 648540858 wvp-GB28181-pro up to 2.7.4. This affects the function GenericFastJsonRedisSerializer of the file src/main/java/com/gen… https://www.cve.org/CVERecord?id=CVE-2026-4860

    Post summary

    The post discloses CVE‑2026‑4860, noting it affects wvp‑GB28181‑pro up to 2.7.4 by targeting the GenericFastJsonRedisSerializer function; it provides limited technical details but no PoC, exploit, or patch information.

    0001082
    56.8K followersView on X

Explore more