
@breno_css, Bruno Milreu and I found CVE-2026-77645, a fully unauthenticated RCE caused by insecure Java deserialization, allowing arbitrary command execution. Always fun to find a classic Java deserialization bug :) https://www.cve.org/CVERecord?id=CVE-2026-77645

