{
  "url": "https://www.videodioggi.com/cve-2026-09-15-en.html",
  "title": "CVE of the day — CVE-2026-90777 (CVSS 8,8, high)",
  "language": "en",
  "published": "2026-09-15T01:04:58.894Z",
  "modified": "2026-09-15T01:04:58.894Z",
  "summary": "CVE-2026-90777: High vulnerability, CVSS 8,8/10, unsafe deserialization type, exploitable remotely, without privileges, with user interaction. ESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weights only=False, allowing arbitrary code execution from..",
  "keywords": [
    "c",
    "cve-2026-90777",
    "vulnerability",
    "high vulnerability",
    "♪",
    "cvs",
    "cybersecurity",
    "cybersecurity",
    "♪",
    "security update"
  ],
  "key_facts": [
    "CVE-2026- 907 — CVE-2026-90777: High gravity, CVSS score 8.8 out of 10 according to the National Vulnerability Database.",
    "Non-safe deserialization — ESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weights only=False, allowing arbitrary code execution from attacker-supplied files. Attackers can craft malicious checkpoint files..",
    "Exposure and mitigation — Vulnerability exploitable remotely, without privileges, with user interaction. Apply the update of the supplier promptly and consult the official notice on NVD."
  ],
  "transcript": "CVE-2026-90777: High gravity, CVSS score 8.8 out of 10 according to the National Vulnerability Database. ESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weights only=False, allowing arbitrary code execution from attacker-supplied files. Attackers can craft malicious checkpoint files.. Vulnerability exploitable remotely, without privileges, with user interaction. Apply the update of the supplier promptly and consult the official notice on NVD.",
  "video": {
    "mp4": "https://www.videodioggi.com/videos/cve-2026-09-15-en.mp4",
    "poster": "https://www.videodioggi.com/videos/cve-2026-09-15-en.jpg",
    "duration_seconds": 20
  },
  "source": "www.videodioggi.com",
  "generator": "videodioggi procedural video engine"
}