Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 499 threats

sql-injectionmetabaseunauthenticated-rcedata-exfiltrationcisa-kevagent-relevant

Metabase, a widely used open-source business intelligence and analytics platform, contains an unauthenticated SQL injection vulnerability that can grant attackers full administrative access to the application. CISA has added this CVE to its Known Exploited Vulnerabilities catalog with a short remediation window, indicating active exploitation in the wild. Successful exploitation exposes connected database credentials and any data accessible through those connections.

prompt-injectionzoteroplugin-vulnerabilityevalrcellm-output-sanitizationchrome-privileged-contextASI01 · Goal HijackingAML.T0051AML.T0054Surface: Tool LayerPropagation: Single Hop

PapersGPT for Zotero 0.6.1 passes unsanitized LLM output directly to window.eval(), allowing arbitrary JavaScript execution in Zotero's privileged chrome context. An attacker can trigger this via prompt injection embedded in a PDF the AI agent reads, a man-in-the-middle on API traffic, or a malicious custom LLM endpoint, resulting in full compromise of the Zotero installation including file read/write and process execution.

SSRFMCPGrafanametadata-endpointinternal-network-pivottool-abuseincomplete-fixASI05 · Unsafe Code ExecutionAML.T0053AML.T0043Surface: Tool LayerPropagation: Single Hop

The mcp-grafana MCP server allows a caller to control the destination host, HTTP method, path, and body of outbound requests via the X-Grafana-URL header and the grafana_api_request tool, enabling server-side request forgery against internal, loopback, and cloud metadata services. This is an incomplete fix for a prior vulnerability (CVE-2026-15583) that stopped credential leakage but left the underlying destination-control flaw unpatched. Given the 9.1 CVSS score and potential for cloud credential theft via metadata endpoints, this is a critical, actively exploitable issue.

SAPcommand-injectionRCEmanufacturinginput-validationcritical-infrastructure

A critical command injection vulnerability affects SAP Manufacturing Integration and Intelligence (MII), allowing a high-privileged attacker to submit crafted input that is insufficiently validated, leading to arbitrary OS command execution. Exploitation could fully compromise confidentiality, integrity, and availability of the affected system. Organizations running SAP MII in manufacturing or industrial environments should prioritize patching.

sapnetweavermemory-corruptionunauthenticated-rcedoserpcritical-infrastructure

A critical unauthenticated vulnerability (CVE-2026-34265) affects SAP NetWeaver Application Server ABAP, stemming from logical errors in DIAG protocol parsing that lead to memory corruption. With a CVSS score of 9.8, attackers can remotely disclose sensitive information or crash affected systems without any authentication, posing severe risk to organizations running SAP ERP environments.

kubernetesauthentication-bypassprivilege-escalationmaasmulti-tenancyagent-relevantai-infrastructureapi-security

CVE-2026-14450 is a critical authentication bypass vulnerability in the Model-as-a-Service (MaaS) API layer fronted by Kuadrant's AuthPolicy gateway. Any pod within the affected Kubernetes cluster can forge the X-MaaS-Username and X-MaaS-Group HTTP headers, which are trusted verbatim without first-party verification, enabling full cross-tenant privilege escalation. This allows attackers to mint ServiceAccount tokens in other tenants' namespaces, revoke arbitrary API keys, and exfiltrate model access configuration data.

routercommand-injectiontelnetfirmwarerceiotnetwork-device

A critical command injection vulnerability exists in the TelnetSSH configuration function of MSI Radix AXE6600 router firmware v781521, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This flaw could be leveraged to fully compromise home and small-office network infrastructure, enabling traffic interception, lateral movement, or botnet recruitment.

routercommand-injectionrcesshfirmwarenetwork-deviceunauthenticated

A critical command injection vulnerability exists in the TelnetSSH configuration function of MSI Radix AXE6600 routers running firmware v781521, allowing remote attackers to execute arbitrary commands with root privileges. Given the CVSS score of 9.8, this flaw is likely remotely exploitable without authentication, making affected devices prime targets for botnet recruitment, traffic interception, or use as network pivot points.

CISA-KEVcommand-injectionload-balancernetwork-applianceactive-exploitationedge-device

A critical command injection vulnerability in Progress Kemp LoadMaster, tracked as CVE-2026-8037 (CVSS 9.6), has been added to CISA's Known Exploited Vulnerabilities catalog after 792 reported exploitation attempts in the wild. The flaw allows attackers to achieve arbitrary command execution on affected load balancer appliances, posing severe risk to organizations relying on this infrastructure for traffic management.

routercommand-injectionrcefirmwareiotunauthenticatednetwork-infrastructure

A critical command injection vulnerability exists in the alg function of MSI Radix AXE6600 router firmware v781521, allowing remote attackers to execute arbitrary commands with root privileges. With a CVSS score of 9.8, this flaw could enable full device takeover, network pivoting, and traffic interception on affected routers.

routercommand-injectionrceiotfirmwareunauthenticated-rce

A critical unauthenticated command injection vulnerability (CVE-2026-71986) exists in the dmz function of MSI Radix AXE6600 router firmware v781521, allowing remote attackers to execute arbitrary commands and gain root access. With a CVSS score of 9.8, this flaw poses severe risk to any network relying on the affected device for perimeter security or connectivity.

routercommand-injectionrceiotnetwork-infrastructureunauthenticated

A critical command injection vulnerability exists in the accesscontrol function of MSI Radix AXE6600 router firmware v781521, allowing remote attackers to execute arbitrary commands with root privileges. Given the CVSS score of 9.8, exploitation likely requires no authentication and results in full device compromise, enabling attackers to intercept, redirect, or manipulate all network traffic passing through the device.

router-vulnerabilitycommand-injectionrceiotnetwork-infrastructureunauthenticated-exploit

A critical unauthenticated command injection vulnerability exists in the urlfilter function of MSI Radix AXE6600 router firmware v781521, allowing remote attackers to execute arbitrary commands with root privileges. Given the CVSS score of 9.8 and remote exploitability without authentication, this vulnerability poses severe risk to any network using affected devices, potentially enabling full network compromise, traffic interception, or pivot points for further attacks.

routercommand-injectionrcefirmwareiotnetwork-deviceunauthenticated

A critical unauthenticated command injection vulnerability exists in the wps.cgi interface of MSI Radix AXE6600 routers running firmware v781521. Remote attackers can inject malicious commands via the pin2g, pin5g, or pin6g parameters to achieve arbitrary command execution with root privileges. This flaw can allow full device takeover, enabling network-level man-in-the-middle attacks, traffic interception, and pivoting into internal networks.

metabasesql-injectionzero-dayunauthenticated-rcebusiness-intelligenceagent-relevantrag-pipelinecredential-exposure

Metabase has disclosed a maximum-severity (CVSS 10.0) zero-day vulnerability being actively exploited in the wild, allowing unauthenticated remote attackers to inject arbitrary SQL and gain administrative access to Metabase instances. No CVE identifier has been assigned yet, but exploitation has already been observed, making this an urgent patching priority for any organization running Metabase for business intelligence or analytics.

d-linkrouterbuffer-overflowrceiotunauthenticatednetwork-perimeter

A critical unauthenticated buffer overflow vulnerability affects D-Link DWR-M961 routers running hardware version C1 with a specific firmware build. Remote attackers can send crafted overly long strings to the test4, ssid2, and username fields of the quicksetup.cgi interface to achieve arbitrary command execution or crash the device. With a CVSS score of 9.8, this flaw poses a severe risk to any exposed device, enabling full device takeover, network pivoting, or denial of service.

D-Linkrouterbuffer-overflowRCEIoTnetwork-applianceCVE-2026-71957

A critical buffer overflow vulnerability exists in D-Link DWR-M961 routers (hardware version C1, firmware 1.1.2_C1_202602110044) in the app.cgi web management interface. A remote, unauthenticated attacker can trigger the flaw by submitting an overly long string to the netAcc.addlist[].name field, enabling arbitrary command execution or causing a denial of service. Given the CVSS score of 9.8, this vulnerability poses a severe risk to any network relying on the affected device for connectivity or perimeter security.

d-linkcommand-injectionrouteriotrceunauthenticatednetwork-infrastructure

A critical unauthenticated command injection vulnerability affects D-Link DWR-M961 routers (hardware version C1, firmware 1.1.2_C1_202602110044). Remote attackers can execute arbitrary commands with root privileges via the netDig.ping.dst parameter in the app.cgi interface, enabling full device takeover. With a CVSS score of 9.8, this vulnerability poses severe risk to any network relying on affected devices for connectivity.

iotroutercommand-injectionrced-linkunauthenticatednetwork-device

A critical unauthenticated command injection vulnerability affects D-Link DWR-M961 routers running firmware prior to 1.1.5_C1_202607071108. Attackers can exploit the fota_url parameter in the LTE FOTA upgrade interface to execute arbitrary commands with root privileges, potentially leading to full device compromise. Given the CVSS score of 9.8 and remote exploitability, this poses a severe risk to any network relying on this device for connectivity.

wordpressplugin-vulnerabilityprivilege-escalationauthentication-bypassai-pluginagent-relevantunauthenticated-rce-equivalent

The AI Copilot – Content Generator WordPress plugin (versions up to 1.5.6) contains an authorization bypass vulnerability allowing unauthenticated attackers to create administrator accounts and fully take over affected sites. The flaw stems from a nonce value being exposed in publicly accessible JavaScript, rendering the plugin's authorization check ineffective on any page rendering the [aiwu-form] shortcode or public chatbot.