Threat Library
Agent-to-agent threats first — conventional coverage one click away.
Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10
Showing 20 of 542 threats
IBM Langflow OSS versions 1.0.0 through 1.10.0 contain a vulnerability allowing an authenticated attacker to read arbitrary files on the host, including the JWT signing key used to issue authentication tokens. With this key, an attacker can forge valid tokens and impersonate any user, effectively bypassing authentication controls within the Langflow agent-building platform.
Langflow, an open-source framework used to build AI agent workflows, contains a server-side request forgery vulnerability caused by weak default configuration and incomplete SSRF protections. An attacker could exploit this to make the Langflow server issue unauthorized requests to internal or cloud-metadata endpoints, potentially exposing sensitive infrastructure or credentials. This is a genuine, credibly documented vulnerability (CVSS 7.7) rather than a speculative or low-quality report.
IBM Langflow, an open-source visual builder for AI agent workflows, contains a path traversal flaw where a malicious flow can fetch attacker-controlled content and write it to arbitrary paths on the server via a crafted Content-Disposition header. An authenticated attacker can abuse this to overwrite configuration, code, or scheduled/startup files, likely leading to full compromise of the Langflow instance. This is a serious framework-level vulnerability requiring only low-privilege authenticated access.
A vulnerability in IBM Langflow's Python Interpreter component allows an authenticated user to execute arbitrary commands with elevated privileges due to improper input validation. This affects Langflow OSS versions 1.0.0 through 1.10.1, and could allow an attacker with low-level access to escalate privileges and take control of the underlying system. Given the CVSS score of 8.8, this is a serious flaw that requires prompt patching.
Microsoft released patches for at least 570 security vulnerabilities in its July 2026 Patch Tuesday, nearly triple the prior month's record-setting release. Microsoft attributes the surge in discovered flaws to AI-assisted vulnerability research, signaling both increased attacker and defender use of AI tooling to find bugs at scale. Organizations face a substantially expanded patching burden across Windows and related Microsoft products.
Researchers at Checkmarx identified seven malicious npm packages targeting the Vite frontend tooling ecosystem, codenamed ViteVenom, which deliver a remote access trojan (RAT). The campaign extends the previously observed ChainVeil operation, leveraging a four-tier blockchain-based command-and-control infrastructure spanning multiple chains including Tron to evade takedown and detection.
HollowByte is a denial-of-service vulnerability in OpenSSL that allows unauthenticated remote attackers to exhaust server memory using a malicious 11-byte payload. The flaw affects any service exposing an OpenSSL-based TLS listener, potentially causing crashes or severe resource exhaustion with minimal attacker effort.
Abbott Laboratories is investigating two separate cybersecurity incidents: unauthorized access to legacy Exact Sciences systems within its Cancer Diagnostics business, and a separate extortion claim involving alleged theft of data from its LabCentral portal. Both incidents are under active investigation and details on scope, data types affected, and threat actor identity remain limited.
A high-severity denial-of-service vulnerability (CVE-2026-9653) affects Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT communication modules due to improper validation of CIP Implicit Connection packets. A network-based attacker can send crafted packets to repeatedly disrupt device connections, though connections recover automatically. Rockwell Automation has released patches for the EN2 and EN3 modules, while the ENBT module is discontinued and will not receive a fix.
Three vulnerabilities (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) affect multiple Rockwell Automation Logix controller families, allowing an unauthenticated remote attacker to send an invalid project or malformed file data that triggers a classic buffer overflow, causing the device to enter a major non-recoverable fault (MNRF). Exploitation results in denial-of-service impacting industrial control processes rather than data confidentiality or integrity loss. No known public exploitation has been reported to CISA at this time.
Open WebUI versions prior to 0.3.14 contain a CORS misconfiguration (allow_origins=*) combined with authenticated cookie-based requests to the /api/v1/functions endpoint, enabling attacker-controlled websites to trigger arbitrary code execution on the server. Exploitation requires an authenticated admin to visit a malicious webpage, after which the attacker can silently deploy or modify server-side functions to achieve RCE. This poses a serious risk to any organization self-hosting Open WebUI as an interface for LLMs or agentic workflows.
Open WebUI versions prior to 0.9.5 contain a stored cross-site scripting vulnerability in the OAuth 'picture' claim handling, where MIME type validation relies on file extension instead of Content-Type headers. This allows attackers to smuggle malicious SVG files that execute script content when rendered, enabling authentication token theft and account takeover of Open WebUI users.
This research demonstrates that LLMs used in Security Operations Centers to analyze network/security logs can be manipulated by adversaries who embed prompt injection payloads directly into log-generating fields (e.g., user-agent strings, hostnames, request paths). Because these logs are stored and later fed verbatim into an LLM's context during analyst queries, the injection persists and executes passively, achieving up to 88.2% attack success across production models for goals like hiding malicious activity, generating false positives, exfiltrating data, or hijacking output. This is academic research with a working benchmark and demonstrated mitigations, not an observed in-the-wild exploit, but it describes a realistic and highly exploitable architectural flaw.
Two members of the Scattered Spider hacking collective, Owen Flowers (18) and Thalha Jubair (20), were sentenced to five and a half years each for a 2024 cyberattack on Transport for London (TfL) that caused an estimated £29 million in losses. The attack rendered 148 TfL systems inoperable and required in-person password resets for all 27,000 employees, highlighting the operational disruption capability of social-engineering-driven threat actors against critical transit infrastructure.
A vulnerability in Anthropic's Claude for Chrome browser extension allows a malicious co-installed extension to simulate user clicks and covertly trigger Claude's predefined AI actions. Since Claude may hold authenticated access to connected services like Gmail, Google Docs, Google Calendar, and Salesforce, an attacker could abuse this to exfiltrate data or perform unauthorized actions on the user's behalf without genuine user consent.
Coca-Cola disclosed that a ransomware attack against its Fairlife dairy subsidiary has disrupted operations, forcing a temporary suspension of Fairlife product manufacturing across the United States. The incident highlights continued targeting of large food and beverage manufacturers by ransomware operators seeking to leverage operational disruption for extortion leverage.
ClickLock is a newly identified macOS information-stealing malware that forcibly terminates all visible user processes to coerce victims into entering their system login password. Once captured, this password can be used to unlock keychains, decrypt stored credentials, and gain deeper system access. The technique represents an evolution in macOS malware social engineering, exploiting user trust in system prompts.
CISA added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: two OS command injection flaws in Fortinet FortiSandbox and a deserialization of untrusted data vulnerability in Microsoft SharePoint. All three are confirmed to be exploited in the wild and pose significant risk to organizations running these products, particularly federal agencies bound by BOD 26-04 remediation timelines.
Siemens has disclosed four vulnerabilities affecting SICAM 8 product firmware (CPCI85 and SICORE base systems) used in energy and critical manufacturing environments. The flaws include an exposed debugging interface, insufficient firmware update signature validation, insecure default OPC UA security settings, and unverified password changes, which combined could lead to denial of service, unauthorized access, or persistent code execution on affected devices. Siemens has released firmware updates (V26.20/V26.20.0) to remediate all four issues.
A high-severity Incorrect Authorization vulnerability affects Adobe Commerce, allowing attackers to bypass security controls and gain unauthorized read and write access without requiring user interaction. This flaw poses significant risk to e-commerce platforms storing sensitive customer, payment, and order data.