Threat Library
Agent-to-agent threats first — conventional coverage one click away.
Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10
Showing 20 of 499 threats
A critical shell injection vulnerability in Wazuh's GitHub Actions workflows allows attackers to execute arbitrary commands by submitting malicious pull requests containing crafted VERSION.json files. Because affected variables are directly interpolated into shell run steps, attackers can achieve command execution and exfiltrate sensitive secrets such as GITHUB_TOKEN and AWS credentials, particularly dangerous on self-hosted runners with broader network and credential access.
FreeRDP versions up to 3.28.0 fail to sanitize CRLF and control characters in the server-controlled TargetNetAddress field of RDP redirection PDUs. A malicious or compromised RDP server can exploit this to inject arbitrary headers or requests into the client's HTTP proxy CONNECT request, potentially enabling request smuggling, proxy authentication bypass, or lateral request injection against internal infrastructure.
FreeRDP versions up to 3.28.0 contain multiple flaws in their custom TLS certificate identity verification logic, allowing an attacker with a trusted or misissued certificate to impersonate legitimate RDP servers. This weakens TLS server authentication and enables man-in-the-middle attacks against RDP sessions, with a critical CVSS score of 9.8.
The Single Sign On For TNG WordPress plugin (versions up to 2.0.0) contains a critical authentication bypass vulnerability allowing unauthenticated attackers to reset any account's password, including administrators. Exploitation leads to complete site takeover with no user interaction or prior authentication required.
The FormGent WordPress plugin (versions up to 1.9.2) contains a critical unauthenticated arbitrary file deletion vulnerability caused by a missing capability check on its REST API endpoint. On Linux servers, attackers can bypass path traversal protections to delete wp-config.php, forcing the site into a fresh-install state that enables full site takeover.
CVE-2026-68771 is a critical unauthenticated remote code execution vulnerability in ComfyUI v0.23.0, a widely used node-based interface for AI/ML pipelines including Stable Diffusion and generative workflows. Attackers can upload a malicious pickle file and trigger deserialization via the LoadTrainingDataset node, achieving arbitrary code execution as the ComfyUI process user with no authentication required.
A critical logic flaw in the popular sentence-transformers Python library allows attackers to bypass the trust_remote_code=False safety control and achieve arbitrary code execution when a model is loaded from a local path. Because a flawed guard condition treats any existing filesystem path as implicitly trusted, malicious Python files placed inside a model directory (referenced via modules.json) will execute automatically at import time, even when developers believe they have disabled remote code execution.
Security researchers at Wiz disclosed a now-patched vulnerability chain in Azure Cosmos DB, dubbed CosmosEscape, that allowed an attacker to escape the Gremlin query sandbox and obtain a platform-wide key granting full read/write access to databases across multiple customer tenants. The flaw originated from a crafted, attacker-controlled Gremlin query that achieved code execution on the underlying host, breaking multi-tenant isolation. Microsoft has remediated the issue; no evidence of in-the-wild exploitation was reported.
JetBrains disclosed a critical authentication bypass vulnerability in TeamCity On-Premises that can be chained to achieve remote code execution. Given TeamCity's role as a CI/CD server, successful exploitation could allow attackers to compromise build pipelines, inject malicious code, and pivot into connected infrastructure. Organizations running affected instances should patch immediately given the high likelihood of active exploitation attempts.
Juggle through version 1.6.0 ships with an exposed and unprotected H2 database web console reachable at /h2-console, secured only by default credentials. Unauthenticated attackers can log in and abuse the H2 CREATE ALIAS technique to invoke Runtime.exec(), achieving arbitrary OS command execution with root privileges on the stock Docker image.
A critical unauthenticated remote code execution vulnerability affects IBM webMethods Integration on-premises versions 10.15 and 10.11, caused by insecure deserialization of untrusted data. With a CVSS score of 9.8, this flaw allows attackers to fully compromise affected servers without any credentials, posing severe risk to organizations relying on webMethods for enterprise integration and workflow orchestration.
A critical SQL injection vulnerability affects UMAI Vision Traffic Analysis System versions 30 through 33, allowing attackers to manipulate backend database queries. With a CVSS score of 9.8, this vulnerability likely permits unauthenticated remote exploitation, posing severe risk to traffic management infrastructure operators.
CVE-2026-44101 is a critical missing-authentication vulnerability in the CHARX OCPP Agent service used to manage backend connections for EV charging infrastructure. An unauthenticated remote attacker can reconfigure the backend connection, leading to denial-of-service conditions and disclosure of confidential data, with a CVSS score of 9.8.
CVE-2026-44091 is a critical unauthenticated vulnerability affecting an MQTT Broker implementation, allowing remote attackers to inject malicious IDs that create unauthorized configuration entries in the system. This can lead to loss of data integrity and system availability, posing significant risk to IoT and industrial environments relying on MQTT for messaging and telemetry.
IBM Langflow OSS versions 1.0.0 through 1.10.0 contain a critical vulnerability allowing a remote, likely unauthenticated attacker to inject and execute arbitrary code due to improper handling of user-supplied input. Given the near-maximum CVSS score of 9.9, this represents a severe risk to any environment running affected Langflow instances, potentially exposing the underlying host, connected agent pipelines, and any credentials or tools accessible to the Langflow server.
IBM Langflow OSS versions 1.0.0 through 1.10.1 contain an improper input validation flaw in the PythonREPL sandbox tool, allowing an attacker to escape the intended execution boundary. Given the CVSS score of 9.9, this likely enables arbitrary code execution on the host running the Langflow agent, posing a critical risk to any deployment exposing this component. Organizations running affected versions should treat this as an urgent patching priority.
Langflow's MCP stdio launcher fails to block dangerous shell environment variables (SHELLOPTS, BASHOPTS, PS4), allowing unauthenticated remote attackers to achieve arbitrary code execution. This is a critical, easily exploitable flaw in a widely used agent orchestration framework's tool-invocation layer.
A maximum-severity vulnerability (CVSS 10.0) in Ruflo, an open-source meta-harness used to orchestrate Claude Code and OpenAI Codex agents via MCP, allows unauthenticated attackers to remotely execute arbitrary commands and poison the agent's persistent memory. This flaw, dubbed RufRoot, affects all versions prior to 3.16.3 and poses severe risk to any deployment exposing the Ruflo MCP interface without proper authentication controls.
A critical vulnerability in Ruby on Rails' Active Storage component (CVE-2026-66066, CVSS 9.5) allows unauthenticated attackers to read arbitrary files from application servers by uploading crafted images. Exposed data can include environment variables and secrets such as secret_key_base, the Rails master key, database passwords, and cloud storage credentials, potentially enabling full application compromise.
Cisco disclosed a high-severity static credential vulnerability in Secure Firewall Management Center (FMC), tracked as CVE-2026-20316, that has been actively exploited in the wild as a zero-day. Attackers leveraged the hardcoded/static credentials to gain unauthorized access to vulnerable FMC devices, potentially enabling control over managed firewalls and network security policy.