Threat Library
Agent-to-agent threats first — conventional coverage one click away.
Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10
Showing 20 of 499 threats
A critical use-after-free vulnerability exists in the Graphics: ImageLib component of Firefox and Thunderbird, carrying a CVSS score of 9.8. Successful exploitation could allow remote code execution via crafted image content rendered by the affected browser or mail client, posing significant risk to any endpoint running unpatched versions.
A critical use-after-free vulnerability (CVE-2026-74940) exists in the Graphics: Text rendering component of Firefox and Thunderbird, carrying a CVSS score of 9.8. Successful exploitation could allow remote code execution, potentially enabling attackers to compromise systems that browse untrusted content or process malicious documents/emails.
A critical use-after-free vulnerability (CVE-2026-74936) exists in the WebAssembly component of Firefox's JavaScript engine, carrying a CVSS score of 9.8. The flaw affects multiple Firefox and Thunderbird release channels and has been patched in the latest versions, indicating high urgency for organizations to update immediately.
TrueConf Server contains a missing authentication vulnerability that allows a remote, unauthenticated attacker with network access to port 4307/TCP to execute arbitrary scripts on the server. This flaw has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild, and requires urgent remediation ahead of the CISA-mandated due date of 2026-08-23.
TrueConf Server is vulnerable to a code injection flaw that allows an unauthenticated remote attacker to escape an isolated execution environment and run arbitrary code on the host via port 4307/TCP. The vulnerability has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild, with remediation required by September 3, 2026.
LangBot, an LLM-based IM bot platform, allows any authenticated user to configure a STDIO MCP server, which the backend uses to launch an arbitrary subprocess with server-level privileges. This means a low-privileged account holder can achieve full remote code execution on the LangBot host, leading to data disclosure, tampering, and service disruption. No fix is currently available, making this a high-priority, actively exploitable weakness.
NSA, CISA, FBI, DOE, and EPA have issued a joint advisory warning of active threat actor targeting of Internet-exposed Siemens S7 Series PLCs (S7-200 through S7-1500) across U.S. critical infrastructure sectors. Threat actors are using AI-assisted development to rapidly generate exploitation scripts—built on the open-source snap7/python-snap7 library—that masquerade as legitimate OT monitoring tools to gain read/write access via the S7comm protocol, likely as reconnaissance and pre-positioning for future disruptive operations.
A critical, easily exploitable vulnerability exists in Oracle Web Services Manager (Web Services Security component) affecting versions 12.2.1.4.0 and 14.1.2.0.0. An unauthenticated attacker with network access via HTTP can compromise the product, gaining unauthorized creation, deletion, modification, and full read access to all data accessible to Oracle Web Services Manager.
A critical unauthenticated remote vulnerability affects Oracle Identity Manager's Legacy UI component within Oracle Fusion Middleware, allowing full compromise via simple HTTP requests. With a CVSS score of 9.8, this flaw requires no authentication or user interaction, making it highly attractive for mass exploitation once technical details or proof-of-concept code emerge. Organizations running affected versions face risk of complete identity infrastructure takeover, including provisioning, credential, and access control data.
A critical vulnerability (CVE-2026-60720, CVSS 9.9) affects the OIM Legacy UI component of Oracle Identity Manager within Oracle Fusion Middleware, allowing a low-privileged attacker with network HTTP access to fully compromise the system. Due to a scope change, successful exploitation can impact other connected products beyond Oracle Identity Manager itself, making this a high-priority patching target for any organization running affected versions.
A critical, easily exploitable vulnerability in Oracle WebLogic Server allows unauthenticated attackers with network access via the T3 or IIOP protocols to fully compromise the server. With a CVSS score of 9.8 and no required user interaction or privileges, this flaw is highly likely to be weaponized rapidly, as historical WebLogic T3/IIOP vulnerabilities have been favored targets for mass exploitation and ransomware precursor activity.
CVE-2026-60591 is a critical, easily exploitable vulnerability in Oracle Hospitality Simphony POS software that allows unauthenticated attackers with network access to compromise data integrity and availability. Affected versions span 19.8 through 19.10.1, and successful exploitation can result in unauthorized data modification/deletion and denial of service. Organizations using Simphony in restaurant, hotel, or retail point-of-sale environments should prioritize patching due to the low complexity and lack of authentication required for exploitation.
A vulnerability in the Splunk MCP Server app (versions below 1.2.1) allows a user with the admin Splunk role to execute arbitrary operating system commands. The flaw stems from unsafe deserialization of stored credential data without type validation. This gives an already-privileged user a path to full host compromise via the MCP integration layer.
A critical vulnerability in the marimo notebook application allows an attacker to achieve arbitrary command execution simply by getting a victim to open a malicious notebook file in edit mode. The malicious payload is hidden inside an MCP server configuration entry and is launched as a subprocess automatically, with no authentication and no need to run any notebook cell.
Agno's PythonTools contains a path traversal flaw that lets an attacker escape the intended sandboxed base_dir by supplying '../' sequences in file arguments to read_file, save_to_file, or run_python_file. This can be triggered either through direct tool calls or by embedding traversal payloads in content the agent processes (prompt injection), resulting in arbitrary file read, write, or code execution at the privilege level of the agent process. Given the high CVSS score and ease of exploitation, this is a critical, actively exploitable vulnerability rather than a theoretical concern.
CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog based on confirmed active exploitation: a Microsoft IKE double-free flaw, a SharePoint authentication bypass, a VMware vCenter path traversal bug, and a macOS improper authentication issue. Under BOD 26-04, FCEB agencies must remediate these on an expedited timeline, and CISA urges all organizations to prioritize patching given evidence of in-the-wild exploitation.
A critical remotely exploitable stack-based buffer overflow has been discovered in TRENDnet TV-IP751WIC IP cameras running firmware 11.03.03, affecting multiple configuration-handling functions within the alphapd web server component. A public exploit exists, and given the device's end-of-life status, no vendor patch is expected, leaving all deployed units permanently vulnerable to remote compromise.
A critical stack-based buffer overflow vulnerability has been discovered in the nginx binary bundled with TRENDnet TEW-WLC100 wireless LAN controllers, triggered by manipulation of the HTTP Server header. The flaw allows unauthenticated remote attackers to execute arbitrary code on the device, and a public exploit is already available, making active exploitation highly likely.
Grav CMS before version 2.0.14 contains a broken access control flaw in the admin plugin's group blueprint, allowing a low-privileged delegated admin.users operator to modify the access field and grant themselves super-admin rights. This enables full administrative takeover of the Grav instance, including scheduler and Twig template evaluation capabilities that can be leveraged for remote code execution.
SpiderFoot fails to sanitize correlation titles derived from untrusted external scan data such as server banners and metadata, allowing attackers to inject malicious HTML/JavaScript. When an operator views the correlations dashboard, the injected script executes in their browser session, potentially exfiltrating stored API keys and session tokens.