Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 1541 threats

agent-relevantAI-agent-abuseLLM-toolingbotnetthreat-actorgemini-cliagentic-malware

A Russian-speaking threat actor known as 'bandcampro' has been observed repurposing Google's open-source Gemini CLI AI tool as an autonomous hacking agent to conduct offensive operations and manage a small-scale botnet. This represents a real-world case of adversaries weaponizing legitimate agentic AI tooling to automate reconnaissance, exploitation, and malware/botnet management tasks.

zoomaccount-takeoverwindowsunauthenticatedvulnerabilityclient-side

Zoom has disclosed a critical vulnerability affecting its desktop client and software development kit (SDK) for Windows that could allow an unauthenticated attacker to hijack user accounts. No public exploitation has been reported yet, but the severity rating indicates high risk if a working exploit emerges. Organizations using Zoom on Windows endpoints should prioritize patching.

investment-fraudlaw-enforcementtakedownsocial-engineeringfinancial-crime

Dutch Police arrested multiple suspects linked to a large-scale international investment fraud scheme that defrauded tens of thousands of victims out of over €100 million. The operation reportedly used deceptive online investment platforms and social engineering tactics to lure victims into fraudulent schemes.

kevcisaactive-exploitationptc-windchillflexplmcisco-ucmssrfimproper-input-validationfederal-agencies

CISA has added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities Catalog: an improper input validation flaw in PTC Windchill and FlexPLM, and an SSRF vulnerability in Cisco Unified Communications Manager. Both are confirmed under active exploitation and pose significant risk, particularly to federal enterprise systems subject to BOD 26-04 remediation timelines.

CISAKEVauthentication-bypassSimpleHelpremote-access-toolactive-exploitationBOD-26-04agent-relevant

CISA has added CVE-2026-48558, an authentication bypass vulnerability in SimpleHelp remote access software, to its Known Exploited Vulnerabilities catalog based on confirmed active exploitation. Federal civilian agencies are required under BOD 26-04 to remediate the flaw on a prioritized timeline, and CISA urges all organizations, public and private, to do the same.

sharepointrcedeserializationmachine-key-theftwebshellpost-exploitationkevmicrosoftagent-relevant

CISA has confirmed active exploitation of three SharePoint Server on-premises vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164) allowing remote code execution, IIS machine key theft, and deserialization-based persistence. Two additional unexploited CVEs (CVE-2026-55040, CVE-2026-58644) have also been disclosed by Microsoft as high-risk if unpatched. All supported on-premises SharePoint versions are affected, prompting CISA to mandate emergency patching under its KEV catalog.

ICSOTABBT-MAC Plusfile-disclosureaccess-control-bypassXSSdenial-of-servicecritical-infrastructurecritical-manufacturing

ABB disclosed four vulnerabilities in T-MAC Plus 4.0-24, a Terminal Management System used in chemical, petroleum, and bulk terminal operations. The most severe issue (CVSS 9.9) allows authenticated users to exfiltrate sensitive files via crafted HTTP GET requests due to IIS misconfiguration, while other flaws enable privilege escalation, stored XSS, and physical-access-based denial of service against Card Reader services. ABB has released version 4.0-25 to remediate all four issues.

kev-catalogknown-exploited-vulnerabilityoracle-ebsknx-protocolprivilege-escalationactive-exploitationfederal-agenciespatch-management

CISA added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: a KNX Protocol account lockout flaw (CVE-2023-4346) and an Oracle E-Business Suite improper privilege management vulnerability (CVE-2026-46817). Under BOD 26-04, FCEB agencies must prioritize remediation of these vulnerabilities on publicly exposed assets due to evidence of active in-the-wild exploitation.

advisorybest-practicesvulnerability-disclosurepolicycisansa

This is not a threat but a joint CISA/NSA and international partner guidance document outlining best practices for establishing a Coordinated Vulnerability Disclosure (CVD) program. It advises software manufacturers and online service providers on creating vulnerability disclosure policies, triage processes, CVE assignment, and use of third-party intermediaries. The goal is to help organizations build collaborative relationships with security researchers and improve overall vulnerability management maturity.

symfonyphpweb-frameworkbypassincomplete-fixagent-relevantrce-riskconfiguration-manipulation

A flaw in Symfony's fix for CVE-2024-50340 fails to properly prevent attacker-controlled environment flags from reaching the application via a discrepancy between parse_str() and the web SAPI's handling of $_GET. This allows remote attackers to craft query strings that manipulate $_SERVER['argv'] to inject --env or --no-debug flags, potentially flipping an application into debug mode or altering its environment configuration. Given the 9.8 CVSS score, this is a critical, low-complexity, remotely exploitable issue affecting a widely used PHP framework.

authentication-bypassjwtoidcsymfonyphpagent-relevantidentity-provider

A flaw in Symfony's OidcTokenHandler::verifyClaims() fails to enforce mandatory audience, issuer, and expiry claims when validating JWTs, allowing a validly signed but incomplete token to bypass verification. This could let an attacker with any validly signed JWT (potentially from an unrelated issuer or expired context) authenticate as a legitimate user against affected Symfony applications. The issue is fixed in Symfony 6.4.40, 7.4.12, and 8.0.12.

symfonyphpauthentication-bypassmtlsclient-certificateweb-frameworkagent-relevant

A critical authentication bypass vulnerability affects Symfony's X509Authenticator component, where an unanchored regex used to parse client certificate distinguished names (DN) can be exploited by an attacker holding any trusted certificate. By embedding 'emailAddress=victim' within an unexpected RDN field like CN, an attacker can impersonate any user identified by email in a mutual TLS authentication scheme.

sharepointrcedeserializationunauthenticatedagent-relevant

CVE-2026-58644 is a critical unauthenticated remote code execution vulnerability in Microsoft Office SharePoint caused by unsafe deserialization of untrusted data. An attacker can exploit this over the network without authentication to achieve full code execution on the SharePoint server, posing severe risk to any organization hosting on-premises SharePoint. Given the CVSS score of 9.8, this vulnerability is likely to be rapidly weaponized following disclosure.

fortinetforticlientemscertificate-validationinformation-disclosuremitmcve-2026-59836

CVE-2026-59836 is an improper certificate validation flaw in Fortinet FortiClientEMS affecting versions 7.2, 7.4.0-7.4.1, and 7.4.3-7.4.5, which could allow an attacker to gain access to sensitive information. The vulnerability likely enables man-in-the-middle style attacks due to insufficient validation of TLS/SSL certificates during communications.

icsotbuilding-automationknxaccount-lockoutphysical-securitycisa-kev

CVE-2023-4346 is a vulnerability in the KNX Protocol's Connection Authorization Option 1 mechanism that allows an attacker to exploit an overly restrictive account lockout to purge all devices lacking additional security options and lock devices via a BCU key. This affects building automation and industrial control deployments using KNX, potentially causing denial of service and loss of device control. CISA has added this CVE to its Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild.

grok-buildxaidata-exfiltrationoverprivileged-agentcli-tooldefault-retentionprivacycoding-agentASI08 · Cascading FailuresSurface: Tool LayerPropagation: None

xAI's Grok Build CLI coding agent was found to upload the entire working directory (and in one reported case, a user's home directory including SSH keys and password manager databases) to xAI's Google Cloud storage without clear user consent. xAI disabled the feature, deleted retained data, and open-sourced the codebase in response to backlash, but this represents a serious real-world data exfiltration incident caused by an overly broad and opaque agent tool/data-retention design rather than a targeted attack.

MCPn8nmulti-tenancyaccess-controltenant-isolationworkflow-backupsIDORASI04 · Agentic Supply ChainSurface: Tool LayerPropagation: Single Hop

A flaw in n8n-MCP's multi-tenant HTTP mode allowed an authenticated tenant to access or delete workflow-version backups belonging to the default scope rather than being confined to their own tenant. This could expose or destroy legacy backup data left over from prior single-tenant deployments or migrations. The issue is fixed in version 2.57.4.

MCPmulti-tenancytenant-isolationcredential-exposuren8nbackup-storageprivilege-escalationASI04 · Agentic Supply ChainSurface: Tool LayerPropagation: Single Hop

n8n-MCP, an MCP server exposing n8n workflow automation to AI assistants, failed to isolate workflow version history backups between tenants when multi-tenancy was enabled. Any authenticated tenant could read, delete, or destroy other tenants' backup snapshots, which contained full node definitions, credential references, and authorization headers. This is a severe cross-tenant data exposure and destruction flaw fixed in version 2.56.1.

MCPsecret-scanning-bypassfile-readrepomixdata-exfiltrationsecurity-boundary-bypassASI05 · Unsafe Code ExecutionSurface: Tool LayerPropagation: Single Hop

Repomix's MCP server contains a flaw where two specific tool flows can be used to register and read arbitrary local files without triggering the secret-scanning safety check that normally protects file reads. This allows an MCP client (or an attacker controlling one) to exfiltrate sensitive local files, including those containing credentials, that were meant to be blocked by the redaction/validation layer.

SSRFcredential-leaktool-schema-abuseelasticsearchstrands-agentsmemory-toolprompt-injection-enabledASI05 · Unsafe Code ExecutionAML.T0051AML.T0053Surface: Tool LayerPropagation: Single Hop

The elasticsearch_memory tool in strands-agents-tools exposed connection parameters like the target host directly to LLM control, allowing a crafted prompt to redirect the tool to an attacker-controlled server. When the api_key parameter was omitted, the tool silently fell back to the operator's environment-stored Elasticsearch API key and sent it to whatever host the LLM specified, leaking the credential via the Authorization header. This is a classic tool-schema over-permissioning issue that turns an LLM-controllable field into a credential exfiltration vector.