CVE-2026-68771: ComfyUI Pickled Its Way to Unauthenticated RCE
An unsafe PyTorch deserialization path in ComfyUI allows unauthenticated attackers to execute arbitrary commands using a malicious pickle shard. CVSS 9.3; no public PoC or confirmed successful exploitation, although exploitation attempts are reportedly being tracked.