Threat Library
Agent-to-agent threats first — conventional coverage one click away.
Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10
Showing 20 of 499 threats
Apache Thrift's c_glib bindings before version 0.24.0 fail to properly validate that a TLS certificate's hostname matches the connected host, allowing an attacker positioned on the network path to present a mismatched but otherwise valid certificate and impersonate a trusted server. This affects any application using the c_glib Thrift client library to establish TLS-secured RPC connections, enabling man-in-the-middle attacks against Thrift-based service communication.
A critical OS command injection vulnerability (CVE-2026-16812) affects Arista VeloCloud Orchestrator On-Prem, a core SD-WAN management platform. CISA has added this to its Known Exploited Vulnerabilities catalog with an unusually short 3-day remediation window, indicating active exploitation in the wild. Successful exploitation grants attackers privileged access to the orchestrator host, threatening confidentiality, integrity, and availability of the entire managed SD-WAN fabric.
Researchers identify 33 protocol-level vulnerabilities across three leading agentic commerce platforms, achieving a 100% attack success rate independent of the AI model used, with three vulnerabilities chaining into a full payment hijack. This is a research paper (not an active exploit in the wild) demonstrating that agent-to-commerce-service protocols, not model behavior, are the primary structural risk in agentic payment systems.
Cl0p-affiliated threat actors (FIN11, Graceful Spider, Lace Tempest) are exploiting internet-exposed PTC Windchill and FlexPLM PLM software through a chained vulnerability enabling unauthenticated remote code execution. The campaign appears focused on data theft and extortion rather than traditional file encryption, consistent with Cl0p's established MO of mass exploitation of enterprise file transfer and PLM platforms.
Panduit IntraVUE versions 3.2.1a14 and earlier contain five vulnerabilities, including a critical confused-deputy proxy flaw (CVSS 10) that allows attackers with IT network access to bypass OT segmentation and manipulate industrial control devices without authentication. Additional flaws expose plaintext credentials via the API, leak host/share filesystem and asset information to unauthenticated users, and use weak encryption enabling pass-the-hash admin credential theft. CISA advises upgrading to version 3.2.1a16 or later; no known public exploitation has been reported to date.
Attackers are actively exploiting an unpatched critical vulnerability in Fastjson 1.x, Alibaba's widely used JSON serialization library for Java, to achieve unauthenticated remote code execution in Spring Boot applications. Security firms ThreatBook and Imperva have observed live exploitation attempts, and no official patch is currently available, leaving deployed systems exposed. The flaw allows a crafted JSON request to trigger code execution with the privileges of the underlying Java process.
Johnson Controls C-CURE 9000 and victor application server products contain three vulnerabilities, including a critical SSRF flaw (CVSS 9.6) in victor Web and a .NET deserialization-related SSRF issue enabling unauthenticated remote code execution on the application server. Successful exploitation could allow attackers with adjacent network access to compromise physical access control and video security systems, including connected client workstations used by security personnel.
SiYuan before v3.7.2 exposes 31 MCP tools via the /mcp kernel endpoint with only a superficial auth check that fails to enforce admin or role restrictions. When the Publish server runs in anonymous mode, a remote unauthenticated attacker can reach this endpoint, steal plaintext secrets from the config file, and write a malicious plugin that achieves code execution on the victim's desktop app at next launch. This is a critical, fully remotely exploitable vulnerability enabling complete administrator takeover.
Security researchers at Zenity Labs disclosed a critical vulnerability, dubbed AgentForger, in OpenAI's ChatGPT Workspace Agents that could allow an attacker to use a single phishing link to covertly create, authorize, and deploy a rogue autonomous AI agent inside a victim organization. OpenAI patched the issue as of June 8, but the flaw highlights significant risks in agent authorization and deployment workflows within enterprise AI platforms.
Security researchers H0j3n and Aniq Fakhrul disclosed Certighost, an exploit chain allowing low-privileged Active Directory users to request a certificate impersonating a Domain Controller. The resulting Kerberos credential inherits directory replication rights, enabling attackers to perform DCSync and extract the krbtgt secret, effectively achieving full domain compromise.
9router versions up to 0.4.59 contain a chained vulnerability allowing a remote, unauthenticated attacker to gain full control of the host system. By logging in with a hardcoded default password, spoofing the Host header to bypass local-only network restrictions, and registering a malicious MCP plugin, an attacker can achieve arbitrary code execution. This is fixed in version 0.4.60 and should be patched immediately given the ease of exploitation and severity.
h2oGPT through version 0.2.1 contains an unauthenticated path traversal vulnerability in its OpenAI-compatible files API that allows attackers to read, write, and delete arbitrary files on the host. Because the default API key is empty and the bearer token is used unsanitized as a path component, attackers can bypass authentication entirely and achieve remote code execution by overwriting startup hooks or application-loaded files.
A Russian state-sponsored espionage group exploited an unpatched zero-day vulnerability in Zimbra's webmail client to conduct a months-long mail collection campaign against Western targets. The exploit required no user interaction beyond opening a malicious email, and enabled theft of 90 days of mail history, full address book contents, browser-saved passwords, and 2FA recovery codes. NSA, CISA, and partner agencies have issued a joint advisory on the campaign.
A maximum-severity vulnerability (CVSS 10.0) exists in Oracle Unified Directory's OUD Core component, allowing an unauthenticated attacker with network access via LDAP to fully compromise the directory service. The vulnerability's scope change indicates successful exploitation can impact additional connected products and systems beyond OUD itself.
A maximum-severity (CVSS 10.0) vulnerability in Oracle Access Manager's Authentication Engine allows unauthenticated, network-based attackers to fully compromise the identity and access management system. The flaw has a scope change, meaning successful exploitation can cascade to impact other integrated applications and services relying on OAM for authentication.
A critical unauthenticated vulnerability (CVE-2026-60355) in Oracle Access Manager's Authentication Engine allows remote attackers to fully compromise the identity and access management system over HTTP with no credentials required. Given the CVSS 9.8 score and full confidentiality, integrity, and availability impact, successful exploitation could grant attackers complete control over enterprise authentication infrastructure. Organizations using Oracle Access Manager for SSO or identity federation are at severe risk of large-scale account takeover and downstream system compromise.
A critical vulnerability (CVSS 9.9) in Oracle Access Manager's Authentication Engine allows a low-privileged attacker with only network access via HTTP to fully compromise the identity and access management system. Due to a scope change, successful exploitation can impact additional connected products beyond Oracle Access Manager itself, making this a high-priority patching target for any organization relying on Oracle Fusion Middleware for SSO and access control.
CVE-2026-60296 is a critical, easily exploitable vulnerability in Oracle Coherence (Oracle Fusion Middleware) that allows an unauthenticated attacker with network access to fully compromise the affected server over TCP. With a CVSS score of 9.8 and no authentication or user interaction required, this flaw poses severe risk to any organization running affected Coherence versions, including those used as caching/data grid layers behind enterprise and AI-driven applications.
A critical unauthenticated remote code execution vulnerability affects Oracle Application Testing Suite version 13.3.0.1, allowing attackers with mere network access to fully compromise the system without any credentials or user interaction. The flaw carries a maximum-impact CVSS score of 9.8, threatening confidentiality, integrity, and availability, and is trivially exploitable, making it a high-priority patching target.
CVE-2026-63764 is a critical unauthenticated SSRF vulnerability in lmdeploy's OpenAI-compatible API server, exploitable via the image_url parameter in chat completions requests. Attackers can chain HTTP redirects to bypass initial URL validation and reach internal services or cloud instance metadata endpoints, potentially exfiltrating cloud credentials. This directly threatens organizations self-hosting lmdeploy to serve multimodal LLMs behind agent or RAG pipelines.