Infoblox NIOS Insecure Deserialization Vulnerability Allowing Remote Code Execution

Vulnerability

A vulnerability exists in Infoblox NIOS versions through 9.0.7, where insecure deserialization can lead to remote code execution. This issue allows unauthenticated attackers to execute arbitrary code or files on the system.

Impact

Exploitation of this vulnerability could result in unauthorized execution of code or files on the affected system.

Remediation

Users can upgrade to Infoblox NIOS version 9.0.8, which includes the fix for this vulnerability. For NIOS versions 8.5.2, 8.6.5, and 9.0.1 through 9.0.7, a version-specific hotfix is available. Instructions for applying this hotfix can be found in the Infoblox support article

Added: Feb 12, 2026, 5:19 PM
Updated: Feb 12, 2026, 9:22 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
7.5
exploitability
5.7
remediation
7.7
relevance
2.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.