Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 1504 threats

wordpressplugin-vulnerabilityrceunauthenticatedfile-uploadweb-application-security

The Sigma Forms Pro WordPress plugin (versions up to 1.4.5) contains a critical vulnerability that allows unauthenticated attackers to achieve remote code execution by exploiting improper capability handling and MIME type validation during form submissions. Several default plugin templates ship with unrestricted file upload fields, making exploitation immediately feasible on default installs without any attacker reconnaissance or configuration changes.

sql-injectionibm-concertremote-exploitdata-breachcve-2026-3627agent-relevant

IBM Concert versions 1.0.0 through 2.3.1 contain a critical SQL injection vulnerability that allows a remote, unauthenticated attacker to manipulate backend database queries. Exploitation could result in unauthorized viewing, modification, or deletion of sensitive application data. With a CVSS score of 9.1, this vulnerability poses significant risk to organizations running unpatched instances.

langflowrceprivilege-escalationsandbox-bypassflow-builderagent-frameworkauthenticated-attackerASI05 · Unsafe Code ExecutionAML.T0011AML.T0053Surface: Tool LayerPropagation: Single Hop

A critical flaw in IBM Langflow OSS allows an authenticated user to escalate from limited flow-building privileges to full arbitrary command execution on the server. By crafting a malicious 'type' field in a saved flow and triggering a build via a wrapper flow, an attacker bypasses the LANGFLOW_ALLOW_CUSTOM_COMPONENTS=false safeguard intended to block custom code execution. This effectively hands the attacker OS-level control of the agent server process.

langflowbroken-access-controlIDORauthenticated-attackeragent-frameworkflow-disclosureASI06 · Memory PoisoningSurface: Tool LayerPropagation: Single Hop

IBM Langflow OSS versions 1.0.0 through 1.11.1 contain an improper authorization flaw that lets any authenticated user execute or read another user's private flows. This is a classic access-control bug in an agent-orchestration framework rather than a novel agentic attack technique, but it can expose proprietary prompts, credentials embedded in flows, and business logic, or allow unauthorized execution of another tenant's automation.

langflownamespace-collisionuser-id-confusiondata-exposuremessage-injectionmulti-tenancyASI02 · Tool MisuseSurface: MemoryPropagation: Single Hop

IBM Langflow OSS versions 1.0.0 through 1.11.1 contain a flaw where user identifiers can collide across namespaces, allowing a remote attacker to access another user's sensitive data or inject messages into their session. This is a serious multi-tenancy isolation failure in a widely used agent-building framework, warranting prompt patching.

langflowpath-traversalfile-readagent-frameworkunauthenticated-accesscveASI08 · Cascading FailuresSurface: Tool LayerPropagation: Single Hop

A path traversal vulnerability in IBM Langflow OSS (versions 1.0.0 through 1.11.1) allows a remote attacker to read arbitrary files on the host system. Langflow is a visual builder for LLM/agent workflows, so this flaw could expose sensitive configuration, credentials, or agent memory/state files stored on disk. This is a genuine, high-severity infrastructure vulnerability rather than a novel agentic attack technique.

langflowimproper-authenticationunauthenticated-accessagent-frameworkflow-executioninformation-disclosureASI02 · Tool MisuseSurface: PlannerPropagation: Single Hop

IBM Langflow OSS versions 1.0.0 through 1.11.1 contain an improper authentication flaw that allows a remote attacker to execute arbitrary flows and access sensitive information without valid credentials. This is a genuine, high-impact vulnerability in a widely used agent/LLM orchestration framework that could let attackers run arbitrary agent pipelines and exfiltrate data. Organizations running affected versions should patch immediately.

langflowrcecode-injectionagent-frameworkauthenticated-attackerflow-builderASI05 · Unsafe Code ExecutionAML.T0011AML.T0053Surface: Tool LayerPropagation: Single Hop

IBM Langflow OSS versions 1.0.0 through 1.11.1 contain a vulnerability that allows a remote authenticated attacker to execute arbitrary code due to improper control over code generation. This affects a widely used low-code framework for building AI agent workflows, meaning any authenticated user could potentially compromise the underlying host or downstream agent components.

langflowssrfagent-frameworkauthenticated-attackernetwork-enumerationASI05 · Unsafe Code ExecutionSurface: Tool LayerPropagation: Single Hop

IBM Langflow OSS versions 1.0.0 through 1.11.1 contain a server-side request forgery (SSRF) vulnerability that allows an authenticated attacker to make the server send unauthorized requests to internal or external systems. This could be used for internal network reconnaissance or as a stepping stone for further attacks, but requires authentication and has moderate severity per its CVSS score of 4.3.

papercutrceauthentication-bypassunauthenticated-rceprint-managementexploit-chainpatch-now

Attackers are actively chaining two vulnerabilities in PaperCut NG and MF print management software to achieve unauthenticated remote code execution. PaperCut has released an emergency patch with additional hardening after confirming exploitation in the wild. Organizations running unpatched PaperCut servers face full server compromise with no authentication required.

blockchaincosmosevmdeficrypto-theftsmart-contract-vulnerabilitysupply-chain

A critical, unpatched balance-handling flaw in the shared Cosmos EVM module was actively exploited between August 20-25, 2026, to drain funds from at least six blockchains built on the Cosmos ecosystem. Cosmos Labs was reportedly aware that all chains running the vulnerable module were exposed prior to exploitation, raising concerns about disclosure timing and coordinated patching failures.

data-extortiongovernmentdata-breachberlinstate-networkdouble-extortion

Berlin's state administrative network was compromised in August 2026, with attackers exfiltrating data and subsequently demanding an extortion payment. The Berlin government has publicly refused to pay, and forensic investigation has revealed additional data outflows from the Senate Department for Mobility, Transport, Climate Protection and Environment, suggesting a broader compromise than initially disclosed.

wordpressplugin-vulnerabilityrcephp-object-injectionunauthenticatedweb-application-securitycms

A maximum-severity vulnerability in the GiveWP WordPress donation plugin allows unauthenticated attackers to execute arbitrary commands on the hosting server. Given GiveWP's widespread use on nonprofit and fundraising websites, this flaw exposes a large number of internet-facing servers to full compromise without requiring any credentials.

print-managementpatch-bypassactive-exploitationrcepath-traversalauthentication-bypass

PaperCut has issued a second emergency patch after security researchers found multiple ways to bypass the initial fixes for two actively exploited vulnerabilities in PaperCut NG and MF print management software. Attackers exploiting these flaws can potentially achieve unauthorized access or remote code execution, prompting urgent re-patching for organizations still running vulnerable versions.

data-breachhealthcareextortionshinyhuntersthird-party-riskpatient-dataPII exposure

McKesson, a major healthcare and pharmaceutical distribution company, disclosed a breach involving unauthorized access to third-party applications, with the ShinyHunters extortion group claiming theft of 284 million patient records. The incident highlights ongoing risks from third-party application compromise and large-scale extortion campaigns targeting healthcare data supply chains.

icsotcisa-advisoryfuel-managementargument-injectionbuffer-overflowrcephplegacy-software

All-Line Equipment Company's Fuel-Boss fuel management systems (Standard, Portal, Master/Slave, and Backflush variants) running PHP 7.1.5 or earlier are vulnerable to two high-severity flaws: an argument injection vulnerability in the PHP imap_open() function and a buffer overflow in PHP-FPM's FastCGI handling. Successful exploitation could allow remote attackers to execute arbitrary OS commands or code on affected systems, posing risk to critical manufacturing, defense, emergency services, and transportation sector operators using this equipment.

ICSIoTcellular-gatewayauthentication-bypassCSRFcleartext-credentialsweak-cryptoMQTTunpatchedno-vendor-fix

The Ebyte NA111-M cellular/MQTT gateway (firmware 9013-2-17) contains 13 vulnerabilities, several rated critical (CVSS 9.8), including missing authentication, client-side authentication bypass, weak cryptographic hashing, and cleartext transmission/storage of credentials including MQTT traffic. Combined, these flaws allow unauthenticated remote attackers to fully compromise the device, gaining administrative control, intercepting or replaying credentials, and disrupting availability. Ebyte has not delivered a patch despite CISA coordination attempts, leaving deployed units permanently exposed absent compensating network controls.

ICSOTdenial-of-serviceCC-LinkMELSECcritical-manufacturingMitsubishi-ElectricCVE-2025-3511

Multiple Mitsubishi Electric FA products, including CC-Link IE TSN modules and MELSEC iQ-R/iQ-F series Ethernet and CPU modules, contain a denial-of-service vulnerability (CVE-2025-3511) in their Ethernet function. A remote attacker can send a specially crafted UDP packet to cause a DoS condition, communication delay, or timeout error, requiring a system reset for recovery in most cases.

langflowa2arceunauthenticatedagent-frameworkcritical-vulnerabilityASI07 · Inter-Agent CommsSurface: ProtocolPropagation: Single Hop

IBM Langflow versions 1.0.0 through 1.11.1 contain a critical flaw in the Agent-to-Agent (A2A) public endpoint that fails to properly enforce security restrictions, allowing a remote unauthenticated attacker to execute arbitrary code. With a CVSS score of 9.8, this is a severe, easily exploitable vulnerability that could grant full control of the affected system.

IBM-iprivilege-escalationunauthenticatedsession-hijackingGUI-vulnerability

A critical unauthenticated privilege escalation vulnerability exists in IBM Administration Runtime Expert (ARE) for i, allowing remote attackers to execute actions under another authenticated user's session. This flaw, rated 9.9 CVSS, poses severe risk to IBM i systems used for enterprise administration and automation, potentially enabling full system compromise without prior credentials.