{"type":"bundle","id":"bundle--b2247f6a-10c1-59c6-9a08-d6fd79bdc1d0","objects":[{"type":"campaign","spec_version":"2.1","id":"campaign--328f95e8-021d-581b-a2ed-a1b9fdf4db4b","created":"2026-09-20T19:55:32.083Z","modified":"2026-09-20T19:55:32.083Z","name":"LMDeploy pickle RCE in disaggregated serving","description":"LMDeploy disaggregated serving is affected by unsafe pickle handling that can lead to remote code execution. Upgrade to the patched release.","aliases":["CVE-2026-76850"],"first_seen":"2026-08-19T00:00:00.000Z","last_seen":"2026-08-19T12:00:00.000Z","objective":"Defensive public threat-intelligence record; see limitations and source references.","external_references":[{"source_name":"NVD CVE-2026-76850","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76850"},{"source_name":"HOL Guard operator write-up","url":"https://hol.org/blog/cve-2026-76850-lmdeploy-pickle-rce-disaggregated-serving"}]}]}