CVE-2026-76850 – LMDeploy

CVSS 9.8 CRITICAL Zero Day – Immediate Deployment

“A malicious peer connection can turn unsafe deserialization into full remote code execution.”

LMDeploy fixes a Critical remote code execution vulnerability affecting disaggregated serving. CVE-2026-76850 allows an unauthenticated remote attacker to direct the engine to an attacker-controlled ZMQ endpoint, where malicious serialized data can execute arbitrary code during deserialization. Deployments without disaggregated serving enabled are not affected. The CVSS score is 9.8, which is Critical severity.

The issue affects LMDeploy versions from 0.9.2 before 0.16.0 and is addressed in version 0.16.0. Public proof-of-concept exploitation is confirmed.

Key Details

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-502
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.