Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 336 threats

ICSOTcritical-manufacturingmemory-corruptionout-of-bounds-writearbitrary-code-executionlocal-exploituser-interaction-required

Rockwell Automation Arena versions up to and including V17.00.00 contain four out-of-bounds write vulnerabilities (CVE-2026-8085, CVE-2026-8312, CVE-2026-8313, CVE-2026-8314) in the model.exe, expmt.exe, linker.exe, and siman.exe (Siman) components. Successful exploitation requires a user to open a malicious file, potentially allowing arbitrary code execution in the context of the current process. No public exploitation has been reported as of publication.

patch-tuesdaymicrosoftvulnerability-managementwindowsai-assisted-discoveryagent-relevant

Microsoft released patches for at least 570 security vulnerabilities in its July 2026 Patch Tuesday, nearly triple the prior month's record-setting release. Microsoft attributes the surge in discovered flaws to AI-assisted vulnerability research, signaling both increased attacker and defender use of AI tooling to find bugs at scale. Organizations face a substantially expanded patching burden across Windows and related Microsoft products.

npmsupply-chainblockchain-c2RATvitemalicious-packagesoftware-supply-chainagent-relevant

Researchers at Checkmarx identified seven malicious npm packages targeting the Vite frontend tooling ecosystem, codenamed ViteVenom, which deliver a remote access trojan (RAT). The campaign extends the previously observed ChainVeil operation, leveraging a four-tier blockchain-based command-and-control infrastructure spanning multiple chains including Tron to evade takedown and detection.

openssldosmemory-exhaustionunauthenticatedtlsagent-relevant

HollowByte is a denial-of-service vulnerability in OpenSSL that allows unauthenticated remote attackers to exhaust server memory using a malicious 11-byte payload. The flaw affects any service exposing an OpenSSL-based TLS listener, potentially causing crashes or severe resource exhaustion with minimal attacker effort.

data-breachextortionhealthcarethird-party-risklegacy-systemsportal-compromise

Abbott Laboratories is investigating two separate cybersecurity incidents: unauthorized access to legacy Exact Sciences systems within its Cancer Diagnostics business, and a separate extortion claim involving alleged theft of data from its LabCentral portal. Both incidents are under active investigation and details on scope, data types affected, and threat actor identity remain limited.

ICSOTdenial-of-serviceCIPRockwell Automationindustrial-control-systemscritical-manufacturing

A high-severity denial-of-service vulnerability (CVE-2026-9653) affects Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT communication modules due to improper validation of CIP Implicit Connection packets. A network-based attacker can send crafted packets to repeatedly disrupt device connections, though connections recover automatically. Rockwell Automation has released patches for the EN2 and EN3 modules, while the ENBT module is discontinued and will not receive a fix.

ICSOTdenial-of-servicebuffer-overflowrockwell-automationcritical-manufacturingfirmwarePLC

Three vulnerabilities (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) affect multiple Rockwell Automation Logix controller families, allowing an unauthenticated remote attacker to send an invalid project or malformed file data that triggers a classic buffer overflow, causing the device to enter a major non-recoverable fault (MNRF). Exploitation results in denial-of-service impacting industrial control processes rather than data confidentiality or integrity loss. No known public exploitation has been reported to CISA at this time.

open-webuicors-misconfigurationrcellm-toolingadmin-takeoveragent-relevant

Open WebUI versions prior to 0.3.14 contain a CORS misconfiguration (allow_origins=*) combined with authenticated cookie-based requests to the /api/v1/functions endpoint, enabling attacker-controlled websites to trigger arbitrary code execution on the server. Exploitation requires an authenticated admin to visit a malicious webpage, after which the attacker can silently deploy or modify server-side functions to achieve RCE. This poses a serious risk to any organization self-hosting Open WebUI as an interface for LLMs or agentic workflows.

xssopen-webuioauthaccount-takeoverllm-uiagent-relevantsupply-chain-component

Open WebUI versions prior to 0.9.5 contain a stored cross-site scripting vulnerability in the OAuth 'picture' claim handling, where MIME type validation relies on file extension instead of Content-Type headers. This allows attackers to smuggle malicious SVG files that execute script content when rendered, enabling authentication token theft and account takeover of Open WebUI users.

scattered-spidersocial-engineeringcritical-infrastructuretransportationlaw-enforcementhelp-desk-attack

Two members of the Scattered Spider hacking collective, Owen Flowers (18) and Thalha Jubair (20), were sentenced to five and a half years each for a 2024 cyberattack on Transport for London (TfL) that caused an estimated £29 million in losses. The attack rendered 148 TfL systems inoperable and required in-person password resets for all 27,000 employees, highlighting the operational disruption capability of social-engineering-driven threat actors against critical transit infrastructure.

browser-extensionai-agentclaudeanthropicprivilege-abuseagent-relevantcross-extension-attackdata-exfiltration

A vulnerability in Anthropic's Claude for Chrome browser extension allows a malicious co-installed extension to simulate user clicks and covertly trigger Claude's predefined AI actions. Since Claude may hold authenticated access to connected services like Gmail, Google Docs, Google Calendar, and Salesforce, an attacker could abuse this to exfiltrate data or perform unauthorized actions on the user's behalf without genuine user consent.

ransomwaremanufacturingOT-disruptionfood-and-beveragesupply-chain-disruptioncritical-infrastructure

Coca-Cola disclosed that a ransomware attack against its Fairlife dairy subsidiary has disrupted operations, forcing a temporary suspension of Fairlife product manufacturing across the United States. The incident highlights continued targeting of large food and beverage manufacturers by ransomware operators seeking to leverage operational disruption for extortion leverage.

macosinfostealercredential-theftsocial-engineeringagent-relevant

ClickLock is a newly identified macOS information-stealing malware that forcibly terminates all visible user processes to coerce victims into entering their system login password. Once captured, this password can be used to unlock keychains, decrypt stored credentials, and gain deeper system access. The technique represents an evolution in macOS malware social engineering, exploiting user trust in system prompts.

kev-catalogfortinetfortisandboxmicrosoft-sharepointos-command-injectiondeserializationactive-exploitationfcebbod-26-04agent-relevant

CISA added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: two OS command injection flaws in Fortinet FortiSandbox and a deserialization of untrusted data vulnerability in Microsoft SharePoint. All three are confirmed to be exploited in the wild and pose significant risk to organizations running these products, particularly federal agencies bound by BOD 26-04 remediation timelines.

ICSOTSCADASiemenscritical-infrastructureenergy-sectorvulnerabilityfirmwareprivilege-escalationdenial-of-service

Siemens has disclosed four vulnerabilities affecting SICAM 8 product firmware (CPCI85 and SICORE base systems) used in energy and critical manufacturing environments. The flaws include an exposed debugging interface, insufficient firmware update signature validation, insecure default OPC UA security settings, and unverified password changes, which combined could lead to denial of service, unauthorized access, or persistent code execution on affected devices. Siemens has released firmware updates (V26.20/V26.20.0) to remediate all four issues.

adobe-commercemagentoe-commerceauthorization-bypassweb-applicationunauthenticated-exploit

A high-severity Incorrect Authorization vulnerability affects Adobe Commerce, allowing attackers to bypass security controls and gain unauthorized read and write access without requiring user interaction. This flaw poses significant risk to e-commerce platforms storing sensitive customer, payment, and order data.

microsoft-365-copilotiosprivilege-escalationaccess-controlagent-relevantai-agent-security

A high-severity access control flaw in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network. Exploitation could grant attackers elevated access to Copilot functionality and connected data without proper authorization, posing risk to enterprise mobile deployments.

windowsrdprceinteger-overflownetwork-exploitableunauthenticatedagent-relevant

CVE-2026-58594 is an integer overflow/wraparound vulnerability in Windows Remote Desktop Protocol (RDP) that allows an unauthorized, remote attacker to execute arbitrary code over the network. With a CVSS score of 8.8, this flaw poses significant risk to any exposed or internally reachable RDP service, enabling potential full system compromise without prior authentication.

windowsrceuse-after-freesstpnetwork-protocolremote-accessvpn

CVE-2026-50694 is a use-after-free vulnerability in Windows' Secure Socket Tunneling Protocol (SSTP) implementation that allows an unauthorized, remote attacker to execute arbitrary code over the network. Given SSTP's role in VPN connectivity, this flaw poses significant risk to organizations relying on Windows-based VPN gateways and remote access infrastructure. The CVSS score of 8.1 reflects high severity with network-based exploitability and no authentication required.

active-directoryrceheap-overflowwindowsnetwork-exploitdomain-controlleragent-relevant

CVE-2026-49164 is a heap-based buffer overflow in Active Directory Domain Services (AD DS) that allows an unauthorized, remote attacker to execute arbitrary code without authentication. Given AD DS's central role in enterprise identity infrastructure, successful exploitation could lead to full domain compromise. The CVSS score of 8.1 reflects high impact combined with network-based, low-complexity attack requirements.