CVE-2026-58659 is a remote code execution vulnerability in PyTorch Lightning through 2.6.5. The vulnerability is caused by the _load_state function importing and executing attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint [truncated]
CVE-2026-44484 is a critical PyTorch Lightning vulnerability publicly published on 2026-05-14 and updated on 2026-05-21. The supplied record says versions 2.6.2 and 2.6.2 introduced functionality consistent with a credential harvesting mechanism, while the NVD CPE data marks 2.6.2 and 2.6.3 as vulnerable. Because the issue is network-reachable, requires no privileges, and no user interaction according to [truncated]