Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 1467 threats

path-traversalpresigned-urlidormulti-tenancyobject-storagetrigger-devcross-tenant-accessASI04 · Agentic Supply ChainSurface: Tool LayerPropagation: Single Hop

Trigger.dev, a platform for managing AI agent workflows, contains a path traversal vulnerability in its packet/object-store signing logic that lets an authenticated caller with any valid environment API key generate presigned URLs pointing into other tenants' storage. This allows reading or overwriting another tenant's task payloads, breaking tenant isolation. The vendor has fixed this in 4.5.0-rc.5.

IDORmulti-tenancybroken-object-level-authorizationagent-platformtask-replaypayload-injectiontrigger.devASI08 · Cascading FailuresSurface: Tool LayerPropagation: Single Hop

Trigger.dev's run replay API looks up task runs by a friendly ID without checking that the run belongs to the caller's environment/tenant, allowing any valid API key holder to replay another tenant's agent task run. This lets an attacker consume victim compute resources and repeat side effects of that run, and in combination with a separate object-store path-traversal bug, potentially inject attacker-controlled payload bytes into the victim's replayed task. The issue is fixed in 4.5.0-rc.4.

unauthenticated-rceagent-tool-abuseexec-sandbox-escapemindsdbscratchpad-toolprompt-injectioncredential-theftASI05 · Unsafe Code ExecutionAML.T0053AML.T0011Surface: Tool LayerPropagation: Single Hop

MindsDB Minds Platform (v26.1.0 and earlier) has an unauthenticated remote code execution vulnerability where attackers can configure their own LLM key via an unprotected settings endpoint, then submit a crafted prompt that directs the 'Anton' agent to invoke its scratchpad tool, which calls exec() on attacker-controlled Python code without sandboxing. This grants full OS command execution as the user running the application, exposing SSH keys, credentials, and environment secrets. This is a critical, fully unauthenticated, trivially exploitable vulnerability warranting immediate patching.

information-disclosuremcperror-handlingssrf-adjacentverbose-errorsASI09 · Human Trust ExploitationSurface: Tool LayerPropagation: None

The CKAN MCP Server, prior to version 0.4.112, leaks raw upstream response bodies and internal exception details (hostnames, internal IPs, DB errors, stack fragments) to callers when errors occur or when the server is redirected to a non-CKAN host. This is a low-severity information disclosure issue rather than a direct compromise vector, but it can aid reconnaissance for further attacks, especially if combined with SSRF-style redirection. The vendor has already released a fix.

MCPpath-traversaltrust-boundarysubprocess-executionclaude-codesupply-chainlocal-privilegedirectory-spoofingASI05 · Unsafe Code ExecutionSurface: Tool LayerPropagation: Single Hop

The Cortex MCP server incorrectly trusts the CLAUDE_PROJECT_DIR environment variable to identify a legitimate Cortex source checkout, using only two file-presence checks as validation. An attacker who convinces a victim to open a malicious repository as their active project in Claude Code can plant these marker files and cause Cortex's open_visualization tool to execute an arbitrary attacker-controlled Python script with the victim's local user privileges.

adobecoldfusionrcecommand-injectionprivilege-escalationpatch-tuesdayagent-relevant

Adobe has released patches for multiple critical vulnerabilities affecting ColdFusion, Commerce, and Campaign Classic, including at least one flaw rated a maximum CVSS score of 10.0. Successful exploitation could allow unauthenticated attackers to achieve arbitrary OS command execution and privilege escalation on affected servers.

security-reportbenchmarkdetection-gaplateral-movementbreach-and-attack-simulationdefense-analytics

Picus Labs' Blue Report 2026 analyzed over 338 million attack simulations across production environments in H1 2026, finding that while perimeter/edge defenses have improved significantly, internal detection and containment capabilities have deteriorated. Attackers are increasingly succeeding not through loud, high-signature attacks but through low-noise techniques that evade internal detection once initial defenses are bypassed.

sharepointauthentication-bypasspoc-exploitmicrosofton-premisesrce-riskagent-relevant

Threat actors are actively exploiting CVE-2026-55040, a critical SharePoint authentication bypass vulnerability, following the public release of proof-of-concept code. The flaw, patched in Microsoft's July 2026 Patch Tuesday, stems from weak authentication controls and carries a CVSS score of 9.1, allowing attackers to bypass security controls on unpatched SharePoint servers.

ransomwareEDR-evasionsafe-modedata-exfiltrationakiradouble-extortion

An Akira ransomware affiliate compromised a target network and rebooted a system into Safe Mode with Networking to disable endpoint detection and response (EDR) protections. The attacker successfully exfiltrated data but failed to deploy the encryption payload, resulting in a partial (extortion-only) compromise rather than full ransomware impact.

law-enforcementfraudcall-center-scaminvestment-scamsocial-engineeringtakedown

Ukrainian authorities dismantled 94 fraudulent call centers that were running investment scams and attempting to gain unauthorized access to victims' bank accounts. Millions in cash were seized during the coordinated operation, representing a significant disruption to organized fraud networks operating in the region.

spywaremercenary-spywaremobile-securityiosnation-statesurveillancetargeted-attack

Apple has issued new 'Threat Notification' alerts warning select iPhone users that they have been targeted by mercenary spyware attacks. These notifications, part of Apple's ongoing threat intelligence program, indicate highly targeted, sophisticated attacks typically associated with commercial spyware vendors like NSO Group or Intellexa rather than broad-based malware campaigns.

ICSOTBACnetdenial-of-serviceSiemensbuilding-automationCVE-2026-59693

A denial-of-service vulnerability (CVE-2026-59693) affects Siemens Desigo DXR and PXC building automation controllers. An attacker with adjacent network access can send a malformed BACnet packet to cause the device to stop responding, requiring a manual reset or reboot to restore functionality. Siemens has released firmware updates to remediate the issue.

ICSSiemensprivilege-escalationpath-traversalvulnerabilityCVECISA-advisorylicensing-server

Siemens License Server (SLS) versions prior to 5.1 and 5.3 are affected by two vulnerabilities: an insecure sudoers policy enabling local privilege escalation to root, and a path traversal flaw allowing remote unauthenticated attackers to read arbitrary files. Siemens has released patched versions and CISA has published an advisory recommending immediate updates.

ICSCISA-advisorySiemensout-of-bounds-readfile-parsingCVE-2026-64629critical-manufacturing

Siemens Parasolid, a 3D geometric modeling kernel used in CAD/CAM/CAE software across critical manufacturing, contains an out-of-bounds read vulnerability (CVE-2026-64629) triggered when parsing malformed X_T files. Successful exploitation could crash the application or allow arbitrary code execution in the context of the current process. Siemens has released patched versions (V38.0.235 and V38.1.230) and users are advised to update.

wordpressplugin-backdoorsupply-chainrcepersistenceweb-shell

A tampered build of Ninja Tables Pro 5.2.11 was distributed through a decommissioned update server, embedding a malicious PHP updater component that grants attackers persistent backdoor access. The compromised plugin creates a passwordless admin account, drops web shells in mu-plugins and uploads directories, and registers scheduled tasks that survive plugin removal, making remediation difficult. Organizations running affected WordPress instances face full site takeover risk, including any hosted applications, APIs, or backend services running on the same host.

wordpresssupply-chainbackdoorplugin-compromiseagent-relevantpersistencerce

A tampered build of Fluent Forms Pro 6.2.7 distributed via a decommissioned update server injects a malicious PHP file that installs a backdoor REST API endpoint, a passwordless administrator account, and persistent scheduled tasks. This constitutes a supply-chain compromise capable of full site takeover, with persistence mechanisms designed to survive plugin removal.

rsyncaccess-control-bypassip-spoofingunauthenticatednetwork-protocolagent-relevant

A critical vulnerability in rsync daemon versions prior to 3.5.0 allows unauthenticated remote attackers to spoof source IP addresses via a crafted PROXY protocol header, bypassing IP-based hosts allow/deny access controls. This enables attackers who can reach the rsync daemon port to gain unauthorized access to file shares that would otherwise be restricted by network-level trust policies.

IBM-iprivilege-escalationauthorization-flawenterprise-serverinsider-threat

A critical vulnerability in IBM i affects versions 7.3 through 7.6, allowing a remote authenticated attacker to escalate privileges through improper authorization checks on high-authority threads. With a CVSS score of 9.6, this flaw could enable an attacker with low-level access to gain full administrative control over the system.

IBM-iprivilege-escalationuncontrolled-search-patharbitrary-code-executionauthenticated-attackenterprise-server

A critical vulnerability in IBM i versions 7.3 through 7.6 allows a remote authenticated attacker to execute arbitrary code by exploiting an uncontrolled search path element. With a CVSS score of 9.9, this flaw could enable low-privileged users to escalate to full system compromise on affected IBM Power Systems servers.

langflowauthenticationbrute-forceaccount-takeoveragent-frameworkrate-limitingASI08 · Cascading FailuresSurface: Human InterfacePropagation: Single Hop

Langflow, an open-source framework used to visually build LLM/agent workflows, contains a flaw allowing unlimited authentication attempts, enabling remote attackers to brute-force user credentials. Given a 9.1 CVSS score, successful exploitation could grant unauthorized access to accounts controlling agent pipelines, connected tools, and stored credentials/secrets.