Threat Library
Agent-to-agent threats first — conventional coverage one click away.
Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10
Showing 20 of 408 threats
CVE-2026-17182 is a critical authentication bypass vulnerability in IBM Db2 Mirror for i affecting versions 7.4, 7.5, and 7.6, allowing remote attackers to bypass authentication controls due to improper validation of request URI path segments. Exploitation could result in unauthorized access, disclosure, or alteration of sensitive database information without requiring credentials. With a CVSS score of 9.8, this vulnerability poses a severe risk to organizations running affected Db2 Mirror deployments.
A critical path traversal vulnerability in IBM Db2 Mirror for i allows remote attackers to write arbitrary files to unintended filesystem locations. With a CVSS score of 9.3, successful exploitation could lead to arbitrary code execution, data corruption, or full system compromise on affected IBM i platforms.
A critical vulnerability in the getgrav/grav-plugin-api plugin (before 1.0.13) allows an attacker holding a minimal-scope API key to mint a new, unscoped super-access API key by submitting an empty scopes array. This bypasses intended scope restrictions and can be chained with configuration write access to achieve full remote code execution on the underlying Grav CMS instance.
A critical path traversal vulnerability in luci-app-openvpn allows authenticated attackers to write arbitrary files outside the intended upload directory, enabling persistent root-level code execution on OpenWrt-based devices. Exploitation involves planting SSH keys in system directories to maintain access across reboots, making this a severe threat to routers and embedded network infrastructure.
A critical vulnerability (CVE-2026-17482) in IBM Documentation Offline versions 1.0.0 through 1.4.1 allows remote attackers to execute arbitrary code due to improper control of file paths. With a CVSS score of 9.8, this flaw is likely exploitable without authentication and poses severe risk to any host running the affected software. Organizations should treat this as an urgent patching priority given the potential for full system compromise.
Adobe has released patches for multiple critical vulnerabilities affecting ColdFusion, Commerce, and Campaign Classic, including at least one flaw rated a maximum CVSS score of 10.0. Successful exploitation could allow unauthenticated attackers to achieve arbitrary OS command execution and privilege escalation on affected servers.
Threat actors are actively exploiting CVE-2026-55040, a critical SharePoint authentication bypass vulnerability, following the public release of proof-of-concept code. The flaw, patched in Microsoft's July 2026 Patch Tuesday, stems from weak authentication controls and carries a CVSS score of 9.1, allowing attackers to bypass security controls on unpatched SharePoint servers.
A tampered build of Ninja Tables Pro 5.2.11 was distributed through a decommissioned update server, embedding a malicious PHP updater component that grants attackers persistent backdoor access. The compromised plugin creates a passwordless admin account, drops web shells in mu-plugins and uploads directories, and registers scheduled tasks that survive plugin removal, making remediation difficult. Organizations running affected WordPress instances face full site takeover risk, including any hosted applications, APIs, or backend services running on the same host.
A tampered build of Fluent Forms Pro 6.2.7 distributed via a decommissioned update server injects a malicious PHP file that installs a backdoor REST API endpoint, a passwordless administrator account, and persistent scheduled tasks. This constitutes a supply-chain compromise capable of full site takeover, with persistence mechanisms designed to survive plugin removal.
A critical vulnerability in rsync daemon versions prior to 3.5.0 allows unauthenticated remote attackers to spoof source IP addresses via a crafted PROXY protocol header, bypassing IP-based hosts allow/deny access controls. This enables attackers who can reach the rsync daemon port to gain unauthorized access to file shares that would otherwise be restricted by network-level trust policies.
A critical vulnerability in IBM i affects versions 7.3 through 7.6, allowing a remote authenticated attacker to escalate privileges through improper authorization checks on high-authority threads. With a CVSS score of 9.6, this flaw could enable an attacker with low-level access to gain full administrative control over the system.
A critical vulnerability in IBM i versions 7.3 through 7.6 allows a remote authenticated attacker to execute arbitrary code by exploiting an uncontrolled search path element. With a CVSS score of 9.9, this flaw could enable low-privileged users to escalate to full system compromise on affected IBM Power Systems servers.
The North Korea-linked Lazarus Group exploited a zero-day vulnerability in Microsoft Windows to gain SYSTEM-level privileges and deploy a previously unseen backdoor. The campaign, part of the long-running Operation Dream Job cyber espionage effort, targeted defense and aerospace organizations in France, Germany, Brazil, and India. The vulnerability has since been patched by Microsoft.
Attackers are actively exploiting a critical vulnerability in Adobe Commerce and Magento platforms that allows hijacking of customer accounts. The flaw is being targeted in the wild shortly after disclosure, putting online retailers and their customer data at risk of unauthorized access and fraud.
A critical flaw (CVE-2026-73268, CVSS 9.9) in the cluster-curator-controller component of multicluster engine (MCE) allows tenants with limited ClusterCurator permissions to inject arbitrary Job specifications that execute with the controller's elevated privileges. Successful exploitation enables arbitrary code execution, privilege escalation, and access to cluster-wide secrets, posing severe risk to multi-tenant Kubernetes/OpenShift environments.
A critical flaw in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM) allows a low-privileged namespace-admin tenant to abuse a highly privileged ServiceAccount via Subscription Custom Resources. This confused-deputy attack enables deployment of arbitrary cluster-scoped resources, leading to full privilege escalation and potential arbitrary code execution across the entire managed cluster.
A critical buffer overflow vulnerability exists in the PROFINET service of an industrial device in its default configuration, allowing unauthenticated remote attackers to crash the device or execute arbitrary code. With a CVSS score of 9.8, this flaw poses severe risk to industrial control system (ICS) and operational technology (OT) environments where the affected device is deployed.
A critical Incorrect Authorization vulnerability in Adobe Campaign Classic (ACC) allows an unauthenticated attacker to execute arbitrary code in the context of the current user without any user interaction required. The maximum CVSS score of 10.0 and changed scope indicate the flaw can escalate impact beyond the vulnerable component itself, making this a top-priority patching target for any organization running ACC.
CISA disclosed eight vulnerabilities in the Mira Hormone Monitor firmware and companion Mira Android App, including missing BLE authentication, hard-coded credentials, and a broken login endpoint that returns valid session tokens for any password. Successful exploitation could allow attackers to hijack user accounts, exfiltrate or forge sensitive reproductive health data, track users physically via BLE, and cause denial-of-service on the device.
A critical Incorrect Authorization vulnerability in Adobe Campaign Classic (ACC) allows attackers to achieve arbitrary code execution in the context of the current user without any user interaction. With a CVSS score of 10.0 and a changed scope, successful exploitation could lead to full compromise of the marketing automation platform and downstream systems it integrates with.