CVE-2026-6588Active Exploitation

MEDIUMCVSS 5.5 · MEDIUM

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A weakness has been identified in serge-chat serge up to 1.4TB. The impacted element is the function download_model/delete_model of the file api/src/serge/routers/model.py of the component Model API Endpoint. Executing a manipulation can lead to missing authentication. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-306

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-20: 3Active Exploitation · 2026-04-20: 1Patch / Workaround · 2026-04-20: 1Technical Details · 2026-04-20: 204-20
Signal classification3 categories
Active Exploitation
133.3%
Disclosure
133.3%
General
133.3%
Referenced assets2 URLs
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-6588 A weakness has been identified in serge-chat serge up to 1.4TB. The impacted element is the function download_model/delete_model of the file api/src/serge/routers/model… https://www.cve.org/CVERecord?id=CVE-2026-6588

    Post summary

    The text reports a CVE‑2026-6588 weakness affecting Serge‑Chat’s model download/delete functions, but provides no evidence of exploitation, PoC, patch, or detailed technical data.

    00000134
    57.2K followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    Serge-chat CVE-2026-6588 is under active exploitation — attackers can delete models due to missing authentication in version 1.4TB. Patch now to prevent unauthorized deletions. #NerdieNews #CyberSecurity #InfoSec #Ransomware #Malware #Microsoft https://t.co/bke6sXhtBn

    Post summary

    CVE-2026-6588 is actively exploited to delete models due to a missing authentication flaw, and an immediate patch is available.

    0000047
    55 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6588 Missing Authentication in Serge-Chat Model API Endpoint Download and Delete Functions https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6588

    Post summary

    The text announces CVE‑2026‑6588 as a missing‑authentication flaw in Serge‑Chat’s API download/delete endpoints, with no PoC, exploit, patch, or active exploitation details.

    0000049
    4.0K followersView on X

Explore more