CVE-2026-76850Disclosure

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine in lmdeploy/pytorch/disagg/conn/engine_conn.py reads peer-to-peer cache-free requests with recv_pyobj(), which deserializes the received bytes with pickle.loads(), and the isinstance check against DistServeCacheFreeRequest runs only after deserialization has already completed. The peer that supplies those bytes is caller-controlled: p2p_connect passes remote_engine_endpoint_info.zmq_address from the request body to connect() on the ZMQ PULL socket, and the POST /distserve/p2p_initialize and /distserve/p2p_connect endpoints in lmdeploy/serve/openai/api_server.py apply no authentication unless the server is started with api_keys, which defaults to None. A remote attacker can direct an engine to pull from a ZMQ endpoint under their control and execute arbitrary code in the engine process. Deployments that do not enable disaggregated serving are not affected, because the receive loop is only started once the migration backend accepts the connection.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-20: 2PoC Mentioned / Linked · 2026-08-20: 1Patch / Workaround · 2026-08-20: 1Technical Details · 2026-08-20: 208-20
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • HOL@HashgraphOnline
    Patch

    CVE-2026-76850: LMDeploy pickle-loads disagg ZMQ peer messages. Unauth POST /distserve/p2p_connect can point the engine at a hostile peer. Affected: lmdeploy >=0.9.2 <0.16.0 Fix: pip install --upgrade lmdeploy==0.16.0 https://hol.org/blog/cve-2026-76850-lmdeploy-pickle-rce-disaggregated-serving https://t.co/GlhBWsDIWS

    Post summary

    The post announces CVE‑2026‑76850 in LMDeploy, explains the unauthenticated misuse of peer messages, and supplies an upgrade fix along with a link likely containing PoC details.

    4901701.3K
    19.2K followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    Disclosure

    🔒 #CyberSecurity CVE-2026-76850: Critical 9.8 Pickle Deserialization RCE in LMDeploy — Detection… "NVD has published CVE-2026-76850, a CVSS 9.8 CRITICAL, network-exploitable vulnerability…" 🔗 https://securityarsenal.com/blog/cve-2026-76850-critical-98-pickle-deserialization-rce-in-lmdeploy-detection-and-remediation-guide #CyberSecurity #ThreatIntel #cve202676850 #critical #cve

    Post summary

    CVE‑2026‑76850 is a critical pickle deserialization RCE in LMDeploy that has been disclosed, with a blog offering detection and remediation guidance.

    0000041
    28 followersView on X

Explore more