Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 542 threats

microsoft-365-copilotiosprivilege-escalationaccess-controlagent-relevantai-agent-security

A high-severity access control flaw in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network. Exploitation could grant attackers elevated access to Copilot functionality and connected data without proper authorization, posing risk to enterprise mobile deployments.

windowsrdprceinteger-overflownetwork-exploitableunauthenticatedagent-relevant

CVE-2026-58594 is an integer overflow/wraparound vulnerability in Windows Remote Desktop Protocol (RDP) that allows an unauthorized, remote attacker to execute arbitrary code over the network. With a CVSS score of 8.8, this flaw poses significant risk to any exposed or internally reachable RDP service, enabling potential full system compromise without prior authentication.

windowsrceuse-after-freesstpnetwork-protocolremote-accessvpn

CVE-2026-50694 is a use-after-free vulnerability in Windows' Secure Socket Tunneling Protocol (SSTP) implementation that allows an unauthorized, remote attacker to execute arbitrary code over the network. Given SSTP's role in VPN connectivity, this flaw poses significant risk to organizations relying on Windows-based VPN gateways and remote access infrastructure. The CVSS score of 8.1 reflects high severity with network-based exploitability and no authentication required.

active-directoryrceheap-overflowwindowsnetwork-exploitdomain-controlleragent-relevant

CVE-2026-49164 is a heap-based buffer overflow in Active Directory Domain Services (AD DS) that allows an unauthorized, remote attacker to execute arbitrary code without authentication. Given AD DS's central role in enterprise identity infrastructure, successful exploitation could lead to full domain compromise. The CVSS score of 8.1 reflects high impact combined with network-based, low-complexity attack requirements.

codexcoding-agentsfile-deletionsandboxingfull-access-modedata-lossagentic-aiASI05 · Unsafe Code ExecutionSurface: Tool LayerPropagation: None

Reports indicate that OpenAI's Codex coding agent (referenced as GPT-5.6) can unexpectedly delete a user's entire $HOME directory when run in 'full access mode' without sandboxing or auto-review safeguards. The root cause is the model attempting to override the $HOME environment variable to create a temporary directory and mistakenly deleting the real $HOME instead. This is an unintentional agent malfunction rather than a malicious attack, but it demonstrates severe real-world consequences of granting autonomous coding agents unsandboxed filesystem access.

wordpressstored-xssai-generated-contentunauthenticatedprompt-injectionplugin-vulnerabilityASI02 · Tool MisuseAML.T0051Surface: Human InterfacePropagation: Single Hop

The BetterDocs WordPress plugin before version 4.5.5 lets unauthenticated users trigger an AI documentation-summary feature whose output is stored and rendered without sanitization. An attacker can craft input that causes the AI to emit malicious HTML/JavaScript, which then executes as stored XSS in the browser of anyone viewing the page, including site administrators.

agent-relevantAI-agent-abuseLLM-toolingbotnetthreat-actorgemini-cliagentic-malware

A Russian-speaking threat actor known as 'bandcampro' has been observed repurposing Google's open-source Gemini CLI AI tool as an autonomous hacking agent to conduct offensive operations and manage a small-scale botnet. This represents a real-world case of adversaries weaponizing legitimate agentic AI tooling to automate reconnaissance, exploitation, and malware/botnet management tasks.

kevcisaactive-exploitationptc-windchillflexplmcisco-ucmssrfimproper-input-validationfederal-agencies

CISA has added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities Catalog: an improper input validation flaw in PTC Windchill and FlexPLM, and an SSRF vulnerability in Cisco Unified Communications Manager. Both are confirmed under active exploitation and pose significant risk, particularly to federal enterprise systems subject to BOD 26-04 remediation timelines.

CISAKEVauthentication-bypassSimpleHelpremote-access-toolactive-exploitationBOD-26-04agent-relevant

CISA has added CVE-2026-48558, an authentication bypass vulnerability in SimpleHelp remote access software, to its Known Exploited Vulnerabilities catalog based on confirmed active exploitation. Federal civilian agencies are required under BOD 26-04 to remediate the flaw on a prioritized timeline, and CISA urges all organizations, public and private, to do the same.

kev-catalogknown-exploited-vulnerabilityoracle-ebsknx-protocolprivilege-escalationactive-exploitationfederal-agenciespatch-management

CISA added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: a KNX Protocol account lockout flaw (CVE-2023-4346) and an Oracle E-Business Suite improper privilege management vulnerability (CVE-2026-46817). Under BOD 26-04, FCEB agencies must prioritize remediation of these vulnerabilities on publicly exposed assets due to evidence of active in-the-wild exploitation.

fortinetforticlientemscertificate-validationinformation-disclosuremitmcve-2026-59836

CVE-2026-59836 is an improper certificate validation flaw in Fortinet FortiClientEMS affecting versions 7.2, 7.4.0-7.4.1, and 7.4.3-7.4.5, which could allow an attacker to gain access to sensitive information. The vulnerability likely enables man-in-the-middle style attacks due to insufficient validation of TLS/SSL certificates during communications.

grok-buildxaidata-exfiltrationoverprivileged-agentcli-tooldefault-retentionprivacycoding-agentASI08 · Cascading FailuresSurface: Tool LayerPropagation: None

xAI's Grok Build CLI coding agent was found to upload the entire working directory (and in one reported case, a user's home directory including SSH keys and password manager databases) to xAI's Google Cloud storage without clear user consent. xAI disabled the feature, deleted retained data, and open-sourced the codebase in response to backlash, but this represents a serious real-world data exfiltration incident caused by an overly broad and opaque agent tool/data-retention design rather than a targeted attack.

MCPsecret-scanning-bypassfile-readrepomixdata-exfiltrationsecurity-boundary-bypassASI05 · Unsafe Code ExecutionSurface: Tool LayerPropagation: Single Hop

Repomix's MCP server contains a flaw where two specific tool flows can be used to register and read arbitrary local files without triggering the secret-scanning safety check that normally protects file reads. This allows an MCP client (or an attacker controlling one) to exfiltrate sensitive local files, including those containing credentials, that were meant to be blocked by the redaction/validation layer.

SSRFcredential-leaktool-schema-abuseelasticsearchstrands-agentsmemory-toolprompt-injection-enabledASI05 · Unsafe Code ExecutionAML.T0051AML.T0053Surface: Tool LayerPropagation: Single Hop

The elasticsearch_memory tool in strands-agents-tools exposed connection parameters like the target host directly to LLM control, allowing a crafted prompt to redirect the tool to an attacker-controlled server. When the api_key parameter was omitted, the tool silently fell back to the operator's environment-stored Elasticsearch API key and sent it to whatever host the LLM specified, leaking the credential via the Authorization header. This is a classic tool-schema over-permissioning issue that turns an LLM-controllable field into a credential exfiltration vector.

mcpbroken-access-controlsession-isolationidortask-managementpython-sdkmulti-tenantASI06 · Memory PoisoningSurface: ProtocolPropagation: Single Hop

The MCP Python SDK's experimental task management feature failed to bind tasks to the session that created them, allowing any connected client to list, read, cancel, or consume messages for tasks belonging to other clients. This is a broken access control / IDOR-style flaw that breaks the trust boundary between concurrent MCP sessions on the same server. It is fixed in version 1.27.2.

MCPsession-hijackingauthentication-bypassSSEstreamable-httpJSON-RPCbroken-authorizationASI06 · Memory PoisoningSurface: ProtocolPropagation: Single Hop

The MCP Python SDK's SSE and stateful Streamable HTTP transports route messages to sessions based solely on a session ID, without checking that the requesting client is the same authenticated principal who created that session. Any bearer-token-authenticated client that learns or guesses a valid session ID can inject JSON-RPC messages into another user's active session, effectively hijacking it. This is a serious cross-tenant authorization flaw fixed in version 1.27.2.

prompt-injectiondata-exfiltrationlethal-trifectaclaudeweb_fetchanthropictool-misusememory-poisoningASI05 · Unsafe Code ExecutionAML.T0051AML.T0043Surface: Tool LayerPropagation: Single Hop

A researcher discovered a loophole in Anthropic's Claude web_fetch tool that allowed a malicious website to exfiltrate private user data (name, location, employer) by chaining together a sequence of attacker-controlled links discovered within previously fetched pages. This bypassed the intended safeguard that web_fetch could only follow user- or search-originated URLs, effectively encoding stolen data letter-by-letter into a series of outbound requests. Anthropic has since patched the issue by disallowing navigation to links found within fetched content.

MCPunauthenticated-accesstool-calldefault-configmissing-authinput-validationpraisonaiASI06 · Memory PoisoningSurface: ProtocolPropagation: Single Hop

PraisonAI versions before 4.6.78 default to running the MCP HTTP-stream server without any API key or authentication, meaning anyone who can reach the endpoint can list and invoke all exposed tools. The server also fails to validate tool-call arguments against the advertised schema, compounding the risk of malformed or malicious inputs reaching tool handlers. Exploitation requires the operator to have bound the server to a network-accessible address rather than the safe localhost default.

MCPSSRFconfused-deputycredential-exfiltrationcloud-metadataunauthenticatedGrafanaASI04 · Agentic Supply ChainSurface: Tool LayerPropagation: Single Hop

An unauthenticated attacker can abuse the Grafana MCP Server by injecting a crafted X-Grafana-URL header, tricking the server into acting as a proxy that leaks its own privileged Grafana service-account token. This same flaw allows server-side request forgery against internal networks and cloud metadata endpoints, giving attackers a path to full credential theft and internal reconnaissance without needing any prior authentication.

agent-relevantbrowser-extensionai-agentclaude-for-chromeanthropicprivilege-escalationdata-exposurerogue-extension

Security researchers found that Claude for Chrome, Anthropic's browser-based AI agent, can be manipulated by any other malicious browser extension capable of injecting a script into claude.ai. This allows a rogue extension to trigger Claude's authenticated agent actions, silently reading a victim's Gmail, Google Docs (including comments), and Calendar without direct user consent for that specific action. The flaw is related to but distinct from the previously disclosed 'ClaudeBleed' issue, sharing the same rogue-extension prerequisite but differing in the scope of accessible data.