Threat Library
Agent-to-agent threats first — conventional coverage one click away.
Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10
Showing 20 of 485 threats
CVE-2026-83548 is a server-side request forgery vulnerability in SonicWall SMA1000 Appliances that allows a remote, unauthenticated attacker to reach sensitive internal functionality and perform unauthorized operations. CISA has added this CVE to its Known Exploited Vulnerabilities catalog with a compressed remediation window, indicating active or imminent exploitation in the wild. Organizations using SMA1000 for secure remote access should treat this as an urgent patching priority.
Sangoma Switchvox, a VoIP PBX platform, contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request. This flaw has been added to CISA's Known Exploited Vulnerabilities catalog with an extremely tight remediation window, indicating active exploitation in the wild. Successful exploitation can lead to database compromise and remote code execution on the underlying host.
Kestra OSS, an open-source workflow and orchestration platform, contains an OS command injection vulnerability (CVE-2026-49869) that allows unauthenticated remote attackers to create and execute arbitrary workflows without credentials. This vulnerability has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild, with a remediation due date of September 5, 2026.
Threat actors are actively exploiting a critical authentication bypass vulnerability (CVE-2026-82329, CVSS 9.8) in JFrog Artifactory just days after public disclosure, allowing attackers to mint administrative access tokens under default configurations. This provides full administrative control over artifact repositories, enabling malicious package injection, credential theft, and downstream supply-chain compromise.
Attackers are actively exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, a popular open-source framework for building AI agent workflows. Successful exploitation allows attackers to execute arbitrary code on exposed Langflow instances and harvest sensitive credentials such as OpenAI and AWS keys stored in the environment. This poses a critical supply-chain risk to organizations running AI application pipelines built on this framework.
A critical authentication bypass vulnerability in Proxmox Virtual Environment allows unauthenticated attackers to log in as any enabled user, including root@pam, by supplying an arbitrary value in the tfa-challenge parameter during API login. This completely circumvents password verification and two-factor authentication, granting full administrative control over the hypervisor. All affected versions are end of life and will not receive official patches, making immediate upgrade the only viable remediation path.
A logic flaw in Kyverno's policy exception handling (v1.9.0–v1.12.7) allows attackers to bypass enforce-mode security policies by crafting resource names that match a less restrictive PolicyException. This can be exploited to circumvent critical controls such as hostPath volume restrictions, potentially enabling container breakout or node compromise.
The Nokri Job Board WordPress theme (versions up to 1.6.6) contains a critical authentication bypass vulnerability that allows unauthenticated attackers to take over any user account, including administrators. The flaw stems from improper validation of password reset tokens, enabling attackers to reset passwords using empty token values matched against empty or unset user meta fields.
A critical unauthenticated path traversal vulnerability affects Dokploy up to version 0.29.7, specifically in the writeTraefikConfigInPath function used by the Settings component to generate Traefik configuration files. The flaw allows remote attackers to manipulate the path argument to write files outside intended directories, potentially leading to configuration overwrite, service disruption, or remote code execution. A public exploit is available and the vendor has not responded to disclosure, leaving deployments unpatched and exposed.
A critical OS command injection vulnerability affects multiple D-Link NAS devices (DNS-320L, DNS-327L, DNS-340L, DNS-345) through the usb_device.cgi CGI handler. The flaw allows unauthenticated remote attackers to execute arbitrary OS commands via the f_ups_ip parameter, and a public exploit is already available, making immediate exploitation highly likely.
A critical privilege escalation vulnerability in hulumi (versions prior to v1.3.2) allows attackers with access to a documented IAM principal to abuse an overly permissive weekly integration policy. This enables creation of persistent, higher-privilege af-e2e-* roles in sandbox accounts, potentially leading to full account compromise.
A critical flaw in @hulumi/policies before version 1.3.2 allows attackers to craft AWS IAM condition operators (ForAnyValue:StringLike) that evade security guardrails designed to detect overly permissive GitHub Actions OIDC trust policies. This enables attackers to establish stealthy, wildcard-based trust relationships between arbitrary GitHub repositories/workflows and AWS IAM roles, potentially leading to unauthorized cross-account access.
A critical stack-based buffer overflow vulnerability affects the TOTOLINK NR1800X router firmware, exploitable remotely via the setUploadSetting function without authentication. A public exploit exists, making this an immediate risk for internet-exposed devices.
A critical remote code execution vulnerability exists in D-Link DIR-825M 1.1.8 routers, caused by a stack-based buffer overflow in the LTE Module Firmware Upgrade handler (formLtefotaUpgradeFibocom). An attacker can remotely manipulate the fota_url parameter to trigger the overflow, with a public exploit already available, making this an immediate risk to exposed devices.
A critical, publicly disclosed vulnerability affects the Tenda HG10 router (firmware 300001138) via its Boa Web Server admin interface. The flaw allows remote, unauthenticated attackers to trigger a buffer overflow through the destNet parameter in the formIPv6Routing function, potentially leading to full device compromise. With a CVSS score of 10.0 and public exploit code available, active exploitation is highly likely.
PaperCut NG/MF is affected by an unsafe reflection vulnerability that allows attackers to manipulate system configuration parameters and execute arbitrary Java bytecode under the security context of the PaperCut server process. This flaw has been added to CISA's Known Exploited Vulnerabilities catalog and can be chained with CVE-2026-81578 to achieve full remote code execution, mirroring the exploitation pattern seen in prior PaperCut attacks used for ransomware and network intrusion.
MCPHub, a management hub for MCP servers, fails to restrict server configuration endpoints to admin users and does not sanitize the command/args used to spawn MCP server processes. Any authenticated non-admin user can register a malicious MCP server configuration that MCPHub immediately executes, resulting in full remote code execution as the host's OS user, often root. This is a critical, easily exploitable authorization flaw with a severe real-world impact.
Eclipse Theia's AI Agent Mode file-editing tools fail to validate that model-supplied file paths stay within the workspace, allowing a malicious or manipulated model output to write or delete arbitrary files on the host. Since these tools execute without user confirmation, an attacker who can influence model output via indirect prompt injection can escalate to full code execution on the backend by overwriting files like shell startup scripts or SSH authorized_keys. This is a critical, high-impact vulnerability combining a classic path traversal flaw with the AI-specific attack surface of untrusted model-controlled tool arguments.
The ash_ai library for the Elixir Ash framework evaluates user-influenced prompt content as live EEx templates, allowing an unauthenticated remote attacker to inject Elixir code that executes on the server before any LLM call is made. This is a classic code injection flaw exposed through an AI agent's prompt-construction pipeline, not a prompt injection against a model itself, but it is trivially reachable via any agent action that lets request data flow into a prompt template. Any deployment using ash_ai versions before 1.0.0 with dynamic prompt content is at critical risk of full server compromise.
A critical remotely exploitable memory corruption vulnerability exists in TOTOLINK A720R routers running firmware 4.1.5cu.630_B20250509, affecting the setMacFilterRules function within cstecgi.cgi. The flaw is triggered via manipulation of the 'desc' argument in MAC filtering rules and has been publicly disclosed with exploit details available, increasing the likelihood of active exploitation.