Security Digest: July 4, 2026 - 10 Critical Vulnerabilities

Today’s highest-risk issues are concentrated in pickle deserialization bypasses affecting AI/model supply chains, plus active-code-execution exposure in NLTK, a Parsec Windows privilege escalation, and a publicly exploitable PHP admin bypass. If your teams use ML model files, Python package scanning, Windows remote access tools, or exposed web admin endpoints, treat this as a same-day response.

· 9 min read

Today’s Security Alert: Act on These 10 Critical Vulnerabilities Now

Executive Summary

Today’s highest-risk issues are concentrated in pickle deserialization bypasses affecting AI/model supply chains, plus active-code-execution exposure in NLTK, a Parsec Windows privilege escalation, and a publicly exploitable PHP admin bypass. If your teams use ML model files, Python package scanning, Windows remote access tools, or exposed web admin endpoints, treat this as a same-day response.

Immediate priorities: patch affected tools, block untrusted model and JAR loading, and audit for suspicious deserialization, admin access, and unexpected SYSTEM-level processes.

Critical Vulnerabilities

CVE-2026-54424: Parsec for Windows SYSTEM-level privilege escalation

  • Impact: An attacker can force parsecd.exe to run as NT AUTHORITY\SYSTEM with a user-controlled AppData value, creating a path to elevation of privilege.
  • Affected Systems: Unity Parsec on Windows hosts through v2026-05-04.0.
  • Immediate Action: Upgrade immediately to Parsec for Windows 150-104a. Review Windows endpoints for unexpected SYSTEM processes tied to Parsec.
  • Mitigation: Remove or restrict Parsec on sensitive systems until patched; monitor for abnormal service launches and environment-variable manipulation.

CVE-2025-71342: picklescan bypass via idlelib gadget

  • Impact: Malicious pickle files can evade scanning and execute code during pickle.load(), enabling remote code execution in PyTorch workflows.
  • Affected Systems: picklescan before 0.0.30; any pipeline relying on it to validate model artifacts.
  • Immediate Action: Upgrade to picklescan 0.0.30 or later. Quarantine untrusted model files now.
  • Mitigation: Treat all external pickle/model artifacts as hostile until rescanned with a fixed version and verified from a trusted source.

CVE-2025-71345: picklescan bypass via torch bottleneck gadget

  • Impact: Attackers can hide code in pickle files that runs during deserialization.
  • Affected Systems: picklescan before 0.0.30.
  • Immediate Action: Patch to 0.0.30+ and block ingestion of untrusted pickles.
  • Mitigation: Rebuild model pipelines so deserialization only occurs from signed, internally produced artifacts.

CVE-2025-71359: picklescan bypass via lib2to3 grammar gadget

  • Impact: Malicious payloads can execute during pickle loading while evading detection.
  • Affected Systems: picklescan before 0.0.29.
  • Immediate Action: Update to the latest fixed release and rescan stored artifacts.
  • Mitigation: Block unknown pickle files at upload, storage, and model-serving boundaries.

CVE-2025-71362: picklescan bypass via numpy.f2py eval path

  • Impact: Arbitrary code can run when a malicious pickle is loaded from an untrusted source.
  • Affected Systems: picklescan before 0.0.33.
  • Immediate Action: Upgrade to 0.0.33+ and disable trust in external pickle inputs.
  • Mitigation: Prefer safer formats where possible; enforce artifact provenance checks.

CVE-2025-71364: picklescan bypass via asyncio subprocess transport gadget

  • Impact: A crafted pickle can trigger arbitrary command execution during deserialization.
  • Affected Systems: picklescan before 0.0.30.
  • Immediate Action: Patch immediately and review any pipelines that deserialize third-party models.
  • Mitigation: Isolate model-processing workloads and restrict outbound command execution on those hosts.

CVE-2025-71369: picklescan bypass via torch datapipes decoder gadget

  • Impact: Attackers can bypass safety checks and execute code from malicious pickle files.
  • Affected Systems: picklescan before 0.0.28.
  • Immediate Action: Upgrade to 0.0.28+ immediately and stop accepting untrusted model files.
  • Mitigation: Add content-signing and allowlist-based artifact controls for ML supply chains.

CVE-2025-71372: picklescan bypass via numpy.f2py getlincoef gadget

  • Impact: Arbitrary Python code can run when a malicious pickle is loaded, enabling supply-chain poisoning.
  • Affected Systems: picklescan before 0.0.33.
  • Immediate Action: Upgrade to 0.0.33+ and revalidate any shared models or datasets.
  • Mitigation: Block deserialization from external feeds until trust controls are in place.

CVE-2026-12252: NLTK Stanford interface classes allow untrusted JAR execution

  • Impact: User-controlled JAR paths can lead to remote code execution via java() and subprocess.Popen().
  • Affected Systems: nltk/nltk 3.9.3 and earlier for StanfordPOSTagger, StanfordNERTagger, StanfordParser, StanfordDependencyParser, and StanfordNeuralDependencyParser.
  • Immediate Action: Upgrade NLTK and block untrusted JAR paths now.
  • Mitigation: Apply SHA256 verification to JARs and only load known-good, internally approved files.

CVE-2026-14622: Restaurant website PHP admin AJAX endpoint missing authentication

  • Impact: Remote attackers can access the vulnerable AJAX endpoint without authentication; public exploit code is available.
  • Affected Systems: jairiidriss restaurant-website-php-mysql up to commit 521428b5b612449df0cf4a5d15ee40cba67f3d35.
  • Immediate Action: Restrict or remove public access to /admin/ajax_files immediately and inspect logs for unauthorized calls.
  • Mitigation: Apply a vendor fix if released; otherwise add server-side authentication, IP restrictions, and temporary WAF rules.

What to Do Now

  1. Patch first: update Parsec, NLTK, and picklescan to the fixed versions listed above.
  2. Stop trusted-by-default deserialization: block untrusted pickle/model files and unverified JARs from entering production.
  3. Lock down exposed admin paths: protect or disable /admin/ajax_files and review internet-facing endpoints.
  4. Verify exposure: inventory systems using PyTorch models, picklescan, NLTK Stanford classes, and Parsec on Windows.
  5. Search for abuse: look for unexpected SYSTEM processes, suspicious Python deserialization activity, and unauthorized admin requests.

Verification steps: confirm installed versions, rescan stored artifacts with fixed tools, and validate that only signed or approved model/JAR files are allowed. Check endpoint and application logs for unusual process launches, deserialization errors, and repeated hits to admin endpoints.

Monitoring recommendations: alert on new pickle.load() usage from external sources, unexpected java/subprocess execution, Parsec service activity under SYSTEM, and web requests to privileged admin routes. Prioritize detections around ML pipelines and build systems, where supply-chain abuse is most likely.

Related Resources

  • Internal: Publish a follow-up blog post on ML artifact hardening and safe deserialization practices.
  • Official vendor advisories: Unity/Parsec security advisory, picklescan release notes, NLTK security update, and project issue tracker for jairiidriss restaurant-website-php-mysql.

Keep reading