Threat Library
Agent-to-agent threats first — conventional coverage one click away.
Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10
Showing 20 of 491 threats
A critical vulnerability in Lighthouse (Submariner's multi-cluster service discovery component) allows an attacker who has compromised a spoke cluster to inject malicious EndpointSlices and ServiceImports into arbitrary namespaces on peer clusters, including sensitive system namespaces. This can lead to traffic hijacking, privilege escalation, and broader compromise of federated Kubernetes/OpenShift environments.
A critical vulnerability in Submariner, a multi-cluster Kubernetes networking tool, allows a malicious spoke cluster to advertise arbitrary and unvalidated network subnets to peer clusters. This enables the attacker to hijack traffic intended for legitimate destinations, rerouting it through an attacker-controlled tunnel for interception, disruption, or man-in-the-middle attacks across the federated cluster mesh.
A critical vulnerability (CVE-2026-16926) affects IBM AIX 7.2, 7.3, and PowerVM VIOS 4.1, allowing remote attackers to overwrite arbitrary files due to improper input sanitization. With a CVSS score of 9.1, this flaw poses significant risk to enterprise Unix/virtualization environments running on IBM Power hardware.
A critical stack-based buffer overflow exists in the mycli binary of TRENDnet TEW-755AP wireless access points, triggered by unsanitized input in the SSID parameter. The vulnerability is remotely exploitable and a public exploit is available, making it an immediate risk for exposed devices. CVSS 9.9 reflects the potential for full device compromise without authentication.
The search-v2-operator, commonly deployed in Kubernetes/OpenShift environments (e.g., Red Hat Advanced Cluster Management), is provisioned with a ClusterRole granting effectively cluster-admin level permissions. This over-privileged configuration allows the operator or any workload/service account leveraging it to impersonate users, forge RBAC bindings, approve CSRs, and manage ManifestWork objects, enabling full cluster takeover.
A critical stack-based buffer overflow vulnerability exists in TRENDnet TEW-823DRU routers (firmware 1.1.02b01) due to unsafe use of strcpy on the wan_l2tp_password parameter in /cgi-bin/wan.cgi. The flaw is remotely exploitable without complex prerequisites, and public exploit code is already available, making it an immediate risk for internet-exposed or compromised-network devices.
CVE-2026-73570 is an unauthenticated OS command injection vulnerability in Synacor Zimbra Collaboration Suite that can be triggered via specially crafted SMTP requests, leading to arbitrary command execution as the Zimbra user. CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog with an unusually short remediation window, indicating active exploitation in the wild. Organizations running ZCS mail servers should treat this as an imminent compromise risk.
Omnigent, an open-source AI agent orchestration framework, fails to validate the dotted Python path an authenticated user supplies for a tool callable when uploading an agent bundle. This allows a low-privilege authenticated user to point a tool at dangerous built-ins like subprocess.check_output, achieving arbitrary command execution with the runner's permissions. The result is full compromise of the runner process, including credentials, environment variables, workspace data, and internal service access.
A flaw in the Omnigent AI agent framework allows a user with only edit access to their own session to tamper with a shared or template agent that isn't properly bound to that session, injecting a malicious stdio MCP server configuration. When other sessions later reuse the poisoned shared agent, attacker-controlled commands execute with the full permissions of the Omnigent runner process, exposing files, credentials, and internal services. This is a critical broken-authorization vulnerability with a CVSS score of 9.0, fixed in version 0.3.0.
A critical vulnerability in the Elementor Pro WordPress plugin allows unauthenticated or low-privileged attackers to upload executable files, leading to full remote code execution on the underlying server. Given Elementor Pro's massive install base, this flaw poses a significant risk of mass exploitation against WordPress-hosted sites and infrastructure.
CVE-2026-60977 is a critical, easily exploitable vulnerability in Oracle WebLogic Server that allows an unauthenticated attacker with network access via RMI to fully compromise the server. With a CVSS score of 9.8, successful exploitation can lead to complete takeover of confidentiality, integrity, and availability. Organizations running affected WebLogic versions should prioritize immediate patching due to the low attack complexity and lack of authentication requirements.
A critical use-after-free vulnerability in the DOM Core & HTML component of Firefox and Thunderbird could allow attackers to execute arbitrary code via crafted web content. The flaw has been patched in Firefox 154, Firefox ESR 140.14/153.1, and Thunderbird 154, 140.14, and 153.1. With a CVSS score of 9.8, unpatched systems are at severe risk of remote exploitation.
A critical use-after-free vulnerability exists in the Graphics: ImageLib component of Firefox and Thunderbird, carrying a CVSS score of 9.8. Successful exploitation could allow remote code execution via crafted image content rendered by the affected browser or mail client, posing significant risk to any endpoint running unpatched versions.
A critical use-after-free vulnerability (CVE-2026-74940) exists in the Graphics: Text rendering component of Firefox and Thunderbird, carrying a CVSS score of 9.8. Successful exploitation could allow remote code execution, potentially enabling attackers to compromise systems that browse untrusted content or process malicious documents/emails.
A critical use-after-free vulnerability (CVE-2026-74936) exists in the WebAssembly component of Firefox's JavaScript engine, carrying a CVSS score of 9.8. The flaw affects multiple Firefox and Thunderbird release channels and has been patched in the latest versions, indicating high urgency for organizations to update immediately.
TrueConf Server contains a missing authentication vulnerability that allows a remote, unauthenticated attacker with network access to port 4307/TCP to execute arbitrary scripts on the server. This flaw has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild, and requires urgent remediation ahead of the CISA-mandated due date of 2026-08-23.
TrueConf Server is vulnerable to a code injection flaw that allows an unauthenticated remote attacker to escape an isolated execution environment and run arbitrary code on the host via port 4307/TCP. The vulnerability has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild, with remediation required by September 3, 2026.
LangBot, an LLM-based IM bot platform, allows any authenticated user to configure a STDIO MCP server, which the backend uses to launch an arbitrary subprocess with server-level privileges. This means a low-privileged account holder can achieve full remote code execution on the LangBot host, leading to data disclosure, tampering, and service disruption. No fix is currently available, making this a high-priority, actively exploitable weakness.
NSA, CISA, FBI, DOE, and EPA have issued a joint advisory warning of active threat actor targeting of Internet-exposed Siemens S7 Series PLCs (S7-200 through S7-1500) across U.S. critical infrastructure sectors. Threat actors are using AI-assisted development to rapidly generate exploitation scripts—built on the open-source snap7/python-snap7 library—that masquerade as legitimate OT monitoring tools to gain read/write access via the S7comm protocol, likely as reconnaissance and pre-positioning for future disruptive operations.
A critical, easily exploitable vulnerability exists in Oracle Web Services Manager (Web Services Security component) affecting versions 12.2.1.4.0 and 14.1.2.0.0. An unauthenticated attacker with network access via HTTP can compromise the product, gaining unauthorized creation, deletion, modification, and full read access to all data accessible to Oracle Web Services Manager.