Threats·Cloud & SaaSBreakingLightLLM Unauthenticated RPyC Insecure Deserialization Exposes GPU Inference Clusters to Remote Code Execution (CVE-2026-103395)An unauthenticated RPyC service in LightLLM visual_only deployments enables remote attackers to execute arbitrary code on GPU clusters via pickle deserialization.CST Newsroom1 Oct 202612 min read