Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 918 threats

nokogirilibxml2use-after-freerubysupply-chainxmldtdxincludeagent-relevant

Nokogiri versions before 1.15.6 and 1.16.x before 1.16.2 bundle a vulnerable version of libxml2 affected by CVE-2024-25062, a use-after-free in the xmlTextReader module. Applications using Nokogiri::XML::Reader with DTD validation and XInclude expansion enabled on untrusted XML input can trigger memory corruption, potentially leading to crashes or code execution.

nokogirirubylibxml2libxsltxml-parsingdenial-of-servicememory-disclosurercesupply-chainagent-relevant

Nokogiri versions before 1.13.2 for CRuby ship vulnerable vendored copies of libxml2 2.9.12 and libxslt 1.1.34, exposing applications to denial-of-service, memory disclosure, and potential remote code execution when processing untrusted XML/XSL input. This is a widely-used Ruby gem for XML/HTML parsing, meaning the vulnerability propagates transitively into any application, service, or pipeline that depends on it.

unrestricted-file-uploadweb-shellrcesoftware-repositorysupply-chain-riskagent-relevant

CVE-2026-16286 is a critical unrestricted file upload vulnerability in TRtek's Software Repository Management product, allowing unauthenticated attackers to upload malicious web shells to the underlying web server. Successful exploitation grants remote code execution, giving attackers full control over the affected host. Given the product's role as a software repository, this flaw poses supply-chain risk to any downstream systems, including AI agent pipelines, that pull artifacts from a compromised instance.

wordpressplugin-vulnerabilityprivilege-escalationunauthenticatedcms-security

The Total Donations plugin for WordPress (versions up to 2.0.5) contains a critical privilege escalation vulnerability that allows unauthenticated attackers to gain administrator-level access. Given the CVSS score of 9.8, this flaw is trivially exploitable and could lead to full site takeover.

gitpythonpythonsupply-chainrcegit-config-injectionagent-relevantci-cddependency-risk

GitPython versions before 3.1.59 mishandle multi-line git-config values during write operations, allowing crafted config entries with embedded newlines to be corrupted into live directives such as core.hooksPath. This enables an attacker who can influence a repository's config file to achieve arbitrary code execution the next time any unrelated GitPython write operation touches that config, with a critical CVSS score of 9.8.

giteacode-injectiongit-hooksrcerepository-write-accesscisa-kevagent-relevantci-cdsupply-chain-risk

Gitea, a widely deployed self-hosted Git service, contains a code injection vulnerability that lets an attacker with repository write access plant a malicious Git hook via the diffpatch API endpoint, resulting in arbitrary shell command execution as the Gitea service account. CISA has added this to its Known Exploited Vulnerabilities catalog with a short remediation window, indicating active exploitation in the wild.

weekly-recapsupply-chaincredential-leakplc-securitygitlabstripeexposed-servicesagent-relevant

This is a weekly aggregated security recap covering multiple loosely-related incidents, including AI-assisted attacks against industrial PLC systems, GitLab-related compromises, and leaked Stripe API keys. The report is high-level and lacks technical depth on specific CVEs, exploit chains, or IOCs, functioning primarily as an industry news digest rather than a single actionable threat profile.

malwaregamingseo-poisoningsocial-engineeringcredential-theftmalvertising

Threat actors are distributing the Weedhack malware family through fake Minecraft client websites that closely mimic legitimate gaming projects, using SEO poisoning to drive traffic. McAfee Labs has blocked over 6,300 access attempts to these malicious sites, indicating an active and sustained campaign targeting gamers, particularly those seeking cheat clients or modified game builds.

ai-coding-toolsopen-source-riskdependency-managementremediation-debtsupply-chainagent-relevant

This is not a discrete attack but an industry advisory piece highlighting how AI coding assistants are rapidly increasing the volume of open-source dependencies introduced into codebases, outpacing security teams' ability to review and remediate vulnerabilities. The resulting backlog of unpatched or unreviewed packages creates a growing attack surface and increases organizational risk of supply-chain compromise.

legalregulatoryprivacydata-protectionchildren-privacyCOPPAnon-security-incident

The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated entities resolving allegations that the platform violated the Children's Online Privacy Protection Act (COPPA) by unlawfully collecting personal data from children under 13 without parental consent. This is a legal and regulatory enforcement action, not a cyberattack, vulnerability disclosure, or malware campaign.

wordpressauthentication-bypasssamlplugin-vulnerabilityprivilege-escalationweb-security

Attackers are actively exploiting two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress, allowing forgery of SAML responses to gain unauthorized administrator access. Sites running vulnerable versions of the plugin are at immediate risk of full site takeover.

NAT bypassrouter vulnerabilityunpatchedresidential gatewayport forwardingbroadband ISPIoT exposurenetwork security

An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers allows remote, unauthenticated attackers to create arbitrary port-forwarding rules, bypassing NAT protections and exposing internal network devices directly to the internet. The flaw affects devices deployed by multiple U.S. broadband providers, putting a large base of residential and small-office networks at risk of direct exposure of internal systems such as NAS devices, cameras, and smart home hubs.

oracleweblogichttp-serverknown-exploited-vulnerabilityCISAaccess-controlagent-relevant

CISA has added CVE-2026-21962, an improper access control vulnerability affecting Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in, to its Known Exploited Vulnerabilities (KEV) catalog based on confirmed active exploitation. Federal civilian agencies are required under BOD 26-04 to remediate this vulnerability on a priority basis, and CISA urges all organizations to do the same given the active exploitation in the wild.

network-deviceauthorization-bypasssyslogremote-exploitedge-deviceDrayTek

Multiple DrayTek VigorSwitch models are affected by a set of unauthorized operation vulnerabilities in syslog-related functions caused by missing authorization checks. A remote, unauthenticated attacker can send crafted requests to modify device configuration, restart services, alter startup configuration, or clear logs, potentially leading to persistent network manipulation, denial of service, or evidence destruction.

network-appliancecommand-injectionpre-authrceedge-devicecritical-infrastructure

A critical pre-authentication command injection vulnerability affects multiple DrayTek VigorSwitch models, allowing remote attackers to execute arbitrary commands with root privileges without any credentials. Given the CVSS score of 9.8 and the device's role as network infrastructure, this flaw poses an immediate risk of full network compromise. Organizations using DrayTek switches at network edges should treat this as an urgent patching priority.

authentication-bypassprivilege-escalationnetwork-device-managementrconfigunauthenticated-rce-pathagent-relevant

rConfig versions 8.0.0 before 8.2.13 contain a critical authentication bypass flaw allowing unauthenticated attackers to self-register accounts that are automatically granted full Administrator privileges. This grants access to stored network device credentials, user data, and API tokens, effectively giving attackers full control over managed network infrastructure.

router-exploitrceunauthenticatedfirmware-vulnerabilityiotnetwork-infrastructurebuffer-overflow

A critical unauthenticated remote code execution vulnerability affects Netis NC63 router firmware through V3.0.0.3327, allowing attackers to gain root access via a crafted HTTP request to the device's web management interface. The vulnerability requires no authentication and no user interaction, making it highly exploitable for mass scanning and botnet recruitment. With a CVSS score of 9.8, this represents a severe risk to any network-edge device running the vulnerable firmware.

iotrouterauthentication-bypassunpatchedpublic-exploitnetwork-infrastructure

A critical authentication bypass vulnerability exists in EFM ipTIME T24000M routers (up to firmware 14.20.0) affecting the httpcon_check_session_url function within the Session Validation Handler. The flaw allows remote attackers to bypass authentication without credentials, and a public exploit is already available. The vendor has not responded to disclosure attempts, leaving affected devices unpatched and exposed.

oraclehttp-serverweblogicaccess-controlkevcisaexploited-in-the-wildagent-relevant

CVE-2026-21962 is an actively exploited improper access control vulnerability in Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in that allows unauthorized creation, deletion, or modification of critical data, as well as unauthorized full access to server-accessible data. CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog with a short remediation window, indicating active in-the-wild exploitation and high urgency for patching.

entra-ididentityazure-admicrosoftcvss-10privilege-escalationagent-relevant

Microsoft patched a maximum-severity (CVSS 10.0) vulnerability in Entra ID, its cloud identity and access management platform, that could allow remote code execution or full identity compromise. Microsoft initially flagged the flaw as exploited in the wild but later corrected this to confirm no active exploitation occurred prior to disclosure. The vulnerability's severity stems from Entra ID's central role in authentication for Microsoft 365, Azure, and third-party enterprise applications.