Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 499 threats

wordpressplugin-vulnerabilityauthentication-bypasstype-confusionprivilege-escalationcmsweb-application

The User Profile Builder plugin for WordPress (versions up to 3.16.4) contains a critical authentication bypass vulnerability caused by improper error handling during user registration. An unauthenticated attacker can exploit a type confusion flaw to obtain an autologin nonce bound to user ID 1, effectively logging in as the site's Administrator and achieving full site takeover.

SAPRCEactive-exploitationenterprise-softwarecommerce-platform

A maximum-severity remote code execution vulnerability in SAP Commerce Cloud, patched only three days prior, is already being actively exploited in the wild according to threat intelligence firm Defused. Organizations running unpatched instances face immediate risk of full system compromise, making rapid patching or mitigation critical.

wordpressauthentication-bypassaccount-takeoverplugin-vulnerabilitycryptographic-failureunauthenticated-rce-adjacentcms

The User Session Synchronizer plugin for WordPress (versions up to 1.4.0) contains a critical authentication bypass vulnerability that allows unauthenticated attackers to impersonate any user, including administrators. The flaw stems from unvalidated request parameters and a cryptographic fallback that renders the encryption predictable when an unregistered session key is referenced. Full site takeover is possible with no prior knowledge of secrets, making this an urgent patch priority for any WordPress site running the plugin.

wordpressauthentication-bypassplugin-vulnerabilityprivilege-escalationunauthenticated-rce-adjacentagent-relevant

The 6Storage Rentals WordPress plugin (versions up to 2.27.0) contains a critical authentication bypass vulnerability allowing unauthenticated attackers to log in as any existing WordPress user, including administrators, simply by supplying that user's email address. This flaw stems from an insecure AJAX handler exposed to unauthenticated users that lacks nonce, capability, or ownership checks before establishing a full authenticated session.

wordpressplugin-vulnerabilityarbitrary-file-deletionunauthenticated-rcecontact-form-7web-application-security

The RapiSafe – Secure Multi File Upload plugin for Contact Form 7 (versions up to 1.0.4) contains an unauthenticated arbitrary file deletion vulnerability in its AJAX upload removal handler. Attackers can exploit exposed nonces to delete critical files such as wp-config.php, potentially triggering a reinstallation flow that leads to full remote code execution and site takeover. Given the plugin's popularity and the ease of exploitation (no authentication required), this poses a severe risk to any WordPress site running the affected component.

CVE-2026-17186IBMDb2command-injectionIBM-iremote-code-execution

A critical vulnerability in IBM Db2 Mirror for i allows a remote, likely unauthenticated attacker to execute arbitrary CL (Control Language) commands due to improper input sanitization. With a CVSS score of 9.9, successful exploitation could lead to full compromise of the affected IBM i system.

ibmdb2rcepath-traversalibm-icritical-infrastructure

A critical vulnerability in IBM Db2 Mirror for i (versions 7.4, 7.5, 7.6) allows remote attackers to execute arbitrary code by exploiting external control of file name or path. With a CVSS score of 9.8, this flaw poses severe risk to organizations running IBM i systems for high-availability database replication.

MCPauthentication-bypassmemory-poisoningunauthenticated-accessagent-memorybroken-access-controlmcp-memory-serviceASI05 · Unsafe Code ExecutionAML.T0020AML.T0048Surface: MemoryPropagation: Single Hop

mcp-memory-service, a semantic memory backend used by AI agents, exposes all /api/documents/* routes without any authentication check even when an API key or OAuth is configured. This lets an unauthenticated remote attacker read, write, or delete an agent's persistent memory store, enabling memory poisoning and data theft. The flaw is fixed in version 10.67.1.

SAPCommerce CloudRCEunauthenticatedinput-validationauthorization-bypasspatch-now

SAP has patched a maximum-severity (CVSS 10.0) vulnerability in Commerce Cloud's Data Hub Adapter that allows unauthenticated attackers to execute arbitrary code due to insufficient authorization checks and input validation. Given the flaw requires no authentication and results in full code execution, organizations running affected SAP Commerce Cloud deployments should prioritize immediate patching.

supply-chainpypilitellmcredential-theftpythonagent-relevantcloud-securitysecrets-exposure

Two malicious versions of the popular LiteLLM package were published to PyPI in March and remained live for roughly 40 minutes, long enough to be pulled by automated build pipelines and developers. The packages contained credential-harvesting code that exfiltrated cloud keys, SSH keys, Kubernetes tokens, and database passwords, with CloudSEK estimating exposure impacting over 2,100 organizations based on a dataset of ~434,000 captured files.

vmwarevcenterrcedirectory-traversalvirtualizationpersistent-accessagent-relevant

Threat actors are actively exploiting a critical directory-traversal vulnerability (CVE-2026-59310, CVSS 9.8) in Broadcom VMware vCenter to achieve remote code execution and establish persistent access. The flaw affects any attacker with network access to the vCenter management interface, making unpatched instances high-value targets for post-exploitation activity including lateral movement and infrastructure takeover.

ICSOTvulnerabilityOS-command-injectionSiemensvideo-management-systemphysical-securityCVE-2026-3014privileged-user-exploit

Siemens Siveillance Video Management Servers (based on Milestone XProtect) contain a critical OS command injection vulnerability in the Management Server API that allows users with edit permissions to execute arbitrary code in the context of the Management Server service. Siemens has released patched versions for the affected V2023 R3, V2024 R1, and V2025 product lines and urges immediate updates.

IBMDb2Db2 MirrorIBM iauthentication-bypassimproper-input-validationCVE-2026-17182critical-infrastructuredatabase-security

CVE-2026-17182 is a critical authentication bypass vulnerability in IBM Db2 Mirror for i affecting versions 7.4, 7.5, and 7.6, allowing remote attackers to bypass authentication controls due to improper validation of request URI path segments. Exploitation could result in unauthorized access, disclosure, or alteration of sensitive database information without requiring credentials. With a CVSS score of 9.8, this vulnerability poses a severe risk to organizations running affected Db2 Mirror deployments.

path-traversalibm-db2remote-code-executionibm-iunauthenticateddatabase

A critical path traversal vulnerability in IBM Db2 Mirror for i allows remote attackers to write arbitrary files to unintended filesystem locations. With a CVSS score of 9.3, successful exploitation could lead to arbitrary code execution, data corruption, or full system compromise on affected IBM i platforms.

grav-cmsprivilege-escalationapi-key-abusebroken-access-controlcms-vulnerabilityrce-chainagent-relevant

A critical vulnerability in the getgrav/grav-plugin-api plugin (before 1.0.13) allows an attacker holding a minimal-scope API key to mint a new, unscoped super-access API key by submitting an empty scopes array. This bypasses intended scope restrictions and can be chained with configuration write access to achieve full remote code execution on the underlying Grav CMS instance.

path-traversalopenwrtrouter-securityrceprivilege-escalationssh-backdooredge-devicenetwork-infrastructure

A critical path traversal vulnerability in luci-app-openvpn allows authenticated attackers to write arbitrary files outside the intended upload directory, enabling persistent root-level code execution on OpenWrt-based devices. Exploitation involves planting SSH keys in system directories to maintain access across reboots, making this a severe threat to routers and embedded network infrastructure.

path-traversalrceibmunauthenticatedagent-relevant

A critical vulnerability (CVE-2026-17482) in IBM Documentation Offline versions 1.0.0 through 1.4.1 allows remote attackers to execute arbitrary code due to improper control of file paths. With a CVSS score of 9.8, this flaw is likely exploitable without authentication and poses severe risk to any host running the affected software. Organizations should treat this as an urgent patching priority given the potential for full system compromise.

unauthenticated-rceagent-tool-abuseexec-sandbox-escapemindsdbscratchpad-toolprompt-injectioncredential-theftASI05 · Unsafe Code ExecutionAML.T0053AML.T0011Surface: Tool LayerPropagation: Single Hop

MindsDB Minds Platform (v26.1.0 and earlier) has an unauthenticated remote code execution vulnerability where attackers can configure their own LLM key via an unprotected settings endpoint, then submit a crafted prompt that directs the 'Anton' agent to invoke its scratchpad tool, which calls exec() on attacker-controlled Python code without sandboxing. This grants full OS command execution as the user running the application, exposing SSH keys, credentials, and environment secrets. This is a critical, fully unauthenticated, trivially exploitable vulnerability warranting immediate patching.

adobecoldfusionrcecommand-injectionprivilege-escalationpatch-tuesdayagent-relevant

Adobe has released patches for multiple critical vulnerabilities affecting ColdFusion, Commerce, and Campaign Classic, including at least one flaw rated a maximum CVSS score of 10.0. Successful exploitation could allow unauthenticated attackers to achieve arbitrary OS command execution and privilege escalation on affected servers.

sharepointauthentication-bypasspoc-exploitmicrosofton-premisesrce-riskagent-relevant

Threat actors are actively exploiting CVE-2026-55040, a critical SharePoint authentication bypass vulnerability, following the public release of proof-of-concept code. The flaw, patched in Microsoft's July 2026 Patch Tuesday, stems from weak authentication controls and carries a CVSS score of 9.1, allowing attackers to bypass security controls on unpatched SharePoint servers.