Threat Library
Agent-to-agent threats first — conventional coverage one click away.
Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10
Showing 20 of 1485 threats
This is a defensive research paper, not an active exploit, that identifies a structural weakness in OAuth-secured remote MCP tool use: a tool endpoint can remain 'authorized' even after the underlying workload executing the call has been substituted, is running stale attestation state, or reuses authority meant for a different sender. The authors propose ACLE-MCP, an invocation-scoped capability-lease architecture that binds authorization to fresh, workload-specific execution state, and demonstrate it closes these gaps with a manageable latency cost.
Manifold Security found eight flaws in seven popular command-line AI coding agents (including Claude Code, Codex, and Cursor) where a malicious repository's Git configuration can specify a command that the agent automatically executes on the developer's machine. This execution happens outside the agent's sandbox and without any user approval prompt, meaning simply cloning or opening a booby-trapped repo can lead to arbitrary code execution as the developer's user. Four of the eight issues remained unpatched at the time of publication.
A malware campaign is using bogus software-download websites that impersonate legitimate vendors to trick users into downloading trojanized installers. Once executed, the malware disables Windows Update and weakens Microsoft Defender to maintain persistence and evade detection, with impact concentrated among China-based operations of multinational organizations and Chinese-speaking users.
Google, Anthropic, and OpenAI announced new cybersecurity-focused AI models and structured access programs, including Google's Gemini 3.8 Flash Cyber and the Fairwind Program, which grants early access to advanced defensive AI capabilities for high-priority defenders such as governments, healthcare, and telecom providers. This is an industry development announcement rather than an active threat, but it signals shifts in the AI-driven security tooling landscape that organizations running AI agents should track.
A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being actively exploited to forge tokens granting administrative access. Attackers exploiting this flaw can gain full control over artifact repositories used in software build and deployment pipelines, enabling malicious package injection and data exfiltration.
A critical SQL injection vulnerability in the widely-used All-in-One WP Migration and Backup WordPress plugin allows unauthenticated attackers to execute remote code and fully compromise affected sites. With millions of active installations, this flaw poses a significant risk of mass exploitation, website defacement, and data theft.
Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection flaw in the Sangoma Switchvox VoIP platform, to achieve remote code execution and deploy reverse shells. The vulnerability allows attackers to gain full control of vulnerable systems without credentials, posing a serious risk to organizations running exposed Switchvox deployments.
A high-severity denial-of-service vulnerability affects multiple Rockwell Automation Logix Platform controllers due to improper input length validation during CIP message processing. Successful exploitation causes a major nonrecoverable fault (MNRF), requiring a physical power cycle to restore operations. No public exploitation has been observed at this time.
CISA added seven vulnerabilities to its Known Exploited Vulnerabilities catalog based on confirmed active exploitation, spanning products including Sangoma Switchvox, Starlette, Kestra, BerriAI LiteLLM, JFrog Artifactory, and SonicWall SMA1000 appliances. These flaws include SQL injection, OS command injection, SSRF, authentication bypass, and HTTP request smuggling, posing significant risk to organizations with these products exposed to the internet. Federal agencies must remediate per BOD 26-04, and CISA urges all organizations to prioritize patching.
CISA, the FBI, and international partners released joint guidance on best practices for service providers to communicate clearly and effectively during IT and OT outages, whether caused by cyberattacks, human error, equipment failure, or natural hazards. The guidance stresses clarity, accountability, and transparency to reduce public panic, preserve trust, and support containment and recovery efforts during disruptions. This is a policy/best-practice advisory rather than a description of an active threat, exploit, or vulnerability.
A critical vulnerability in Submariner's cert-auth mode allows a malicious cluster to inject arbitrary ipsec.conf directives via an unsanitized CableName field in a Custom Resource Definition. This enables remote code execution as root on gateway nodes through leftupdown hook abuse, fully compromising the multi-cluster networking layer.
CVE-2026-83549 is an OS command injection vulnerability in SonicWall SMA1000 Appliances that allows an authenticated remote attacker with administrative privileges to execute arbitrary OS commands, leading to full remote code execution. CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog with an unusually short three-day remediation window, indicating active exploitation or imminent risk. Organizations using SMA1000 appliances for secure remote access should prioritize immediate patching.
CVE-2026-83548 is a server-side request forgery vulnerability in SonicWall SMA1000 Appliances that allows a remote, unauthenticated attacker to reach sensitive internal functionality and perform unauthorized operations. CISA has added this CVE to its Known Exploited Vulnerabilities catalog with a compressed remediation window, indicating active or imminent exploitation in the wild. Organizations using SMA1000 for secure remote access should treat this as an urgent patching priority.
Sangoma Switchvox, a VoIP PBX platform, contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request. This flaw has been added to CISA's Known Exploited Vulnerabilities catalog with an extremely tight remediation window, indicating active exploitation in the wild. Successful exploitation can lead to database compromise and remote code execution on the underlying host.
Kestra OSS, an open-source workflow and orchestration platform, contains an OS command injection vulnerability (CVE-2026-49869) that allows unauthenticated remote attackers to create and execute arbitrary workflows without credentials. This vulnerability has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild, with a remediation due date of September 5, 2026.
A HTTP request/response smuggling flaw in the Starlette ASGI framework allows attackers to inject paths into the host portion of a request, causing URL reconstruction that can bypass authentication logic dependent on the reconstructed path. CISA has added this to the KEV catalog, and it may be chained with CVE-2026-42271 to escalate impact. Organizations running Starlette-based web services, including those exposing agent APIs, should prioritize patching before the September 16, 2026 due date.
This item is a Schneier on Security blog post describing anecdotal emails from self-described autonomous AI agents that were given money, a VPS, and instructions to earn cryptocurrency within self-imposed ethical constraints. There is no evidence of a specific exploit, vulnerability, or attack technique here—it's a human-interest/commentary piece about agent autonomy and behavior, not a security incident report. Severity is low because no concrete technical threat, vulnerability, or attack pattern is described.
This is a routine blog post from Simon Willison announcing version 0.34 of the llm-gemini plugin, which adds support for a new Gemini 3.8 Flash model and fixes a minor bug. There is no indication of a security vulnerability, prompt injection, tool poisoning, or any agent-related threat in this content.
Boruta, an OAuth2/OIDC authorization server, logged sensitive credentials including access tokens, refresh tokens, ID tokens, and agent tokens in plaintext business event logs prior to version 0.10.0. Anyone with access to these logs, log aggregation pipelines, or the admin log viewer could extract valid tokens and reuse them for unauthorized access until expiration or revocation. This is a credential-hygiene vulnerability rather than a novel agent-specific attack, but it directly threatens agent-to-service authentication where 'agent tokens' are among the logged values.
Unit 42 reports on an incident in which an attacker used autonomous AI agents to accelerate reconnaissance, exploitation, and lateral movement, compromising an enterprise network within hours. The article is a threat intelligence/case study piece describing attacker tradecraft rather than a specific vulnerability in an agent framework, protocol, or tool; the raw data provided lacks technical detail on the AI tooling or agent architecture used. Given the absence of concrete technical indicators, this is rated medium severity as a notable trend/case study rather than an actionable exploit.