Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 408 threats

zero-daycommand-injectionnetwork-infrastructureSD-WANactive-exploitationedge-deviceRCE

Arista disclosed and patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator (VCO) deployments that has been actively exploited in the wild. Attackers can leverage the flaw to execute arbitrary commands on the orchestrator, potentially gaining control over SD-WAN management infrastructure. Organizations running on-premises VCO instances should patch immediately given confirmed exploitation.

fastjsonjavarcezero-dayopen-sourcesupply-chaindeserializationagent-relevant

Threat actors are actively exploiting an unpatched remote code execution vulnerability in the widely-used FastJson Java library, targeting US-based organizations. The flaw requires no authentication or user interaction, making it highly attractive for mass exploitation and initial access into enterprise networks.

apache-thriftrpcout-of-bounds-readinput-validationcppagent-relevantrag-pipelinemicroservices

CVE-2026-58662 is a critical out-of-bounds read vulnerability in Apache Thrift's C++ bindings caused by improper validation of specified quantity in input, affecting all versions before 0.24.0. Attackers can exploit this by sending crafted Thrift messages to trigger memory over-reads, potentially leading to information disclosure, service crashes, or further exploitation depending on the deployment context.

apache-thriftout-of-bounds-readrpcmemory-corruptionopen-sourceagent-relevant

Apache Thrift's c_glib bindings prior to version 0.24.0 contain an out-of-bounds read vulnerability with a CVSS score of 9.1, indicating potential for information disclosure or denial of service. Apache Thrift is a widely used cross-language RPC framework, and this flaw could be exploited by processing malicious serialized data through affected bindings.

apache-thriftrpcbuffer-overflowmemory-corruptionagent-relevantsupply-chain-componentcpp

A critical heap-based buffer overflow has been identified in the C++ bindings of Apache Thrift, a widely used cross-language RPC framework, affecting all versions prior to 0.24.0. The vulnerability carries a CVSS score of 9.8, indicating remote exploitability with low attack complexity and potential for full system compromise. Organizations using Thrift-based services must upgrade immediately to mitigate risk of remote code execution or denial of service.

apache-thrifttlscertificate-validationmitmagent-relevantrpcsupply-chain-dependency

Apache Thrift's c_glib bindings before version 0.24.0 fail to properly validate that a TLS certificate's hostname matches the connected host, allowing an attacker positioned on the network path to present a mismatched but otherwise valid certificate and impersonate a trusted server. This affects any application using the c_glib Thrift client library to establish TLS-secured RPC connections, enabling man-in-the-middle attacks against Thrift-based service communication.

CISA-KEVSD-WANcommand-injectionnetwork-infrastructureedge-devicepre-auth-suspected

A critical OS command injection vulnerability (CVE-2026-16812) affects Arista VeloCloud Orchestrator On-Prem, a core SD-WAN management platform. CISA has added this to its Known Exploited Vulnerabilities catalog with an unusually short 3-day remediation window, indicating active exploitation in the wild. Successful exploitation grants attackers privileged access to the orchestrator host, threatening confidentiality, integrity, and availability of the entire managed SD-WAN fabric.

Cl0pFIN11ransomwaredata-extortionPLMRCEpre-authPTC-WindchillFlexPLM

Cl0p-affiliated threat actors (FIN11, Graceful Spider, Lace Tempest) are exploiting internet-exposed PTC Windchill and FlexPLM PLM software through a chained vulnerability enabling unauthenticated remote code execution. The campaign appears focused on data theft and extortion rather than traditional file encryption, consistent with Cl0p's established MO of mass exploitation of enterprise file transfer and PLM platforms.

ICSOTindustrial-control-systemsCISAplaintext-passwordconfused-deputypass-the-hashweak-encryptioncritical-infrastructure

Panduit IntraVUE versions 3.2.1a14 and earlier contain five vulnerabilities, including a critical confused-deputy proxy flaw (CVSS 10) that allows attackers with IT network access to bypass OT segmentation and manipulate industrial control devices without authentication. Additional flaws expose plaintext credentials via the API, leak host/share filesystem and asset information to unauthenticated users, and use weak encryption enabling pass-the-hash admin credential theft. CISA advises upgrading to version 3.2.1a16 or later; no known public exploitation has been reported to date.

fastjsonjavarceunpatchedspring-bootzero-dayagent-relevantsupply-chain-risk

Attackers are actively exploiting an unpatched critical vulnerability in Fastjson 1.x, Alibaba's widely used JSON serialization library for Java, to achieve unauthenticated remote code execution in Spring Boot applications. Security firms ThreatBook and Imperva have observed live exploitation attempts, and no official patch is currently available, leaving deployed systems exposed. The flaw allows a crafted JSON request to trigger code execution with the privileges of the underlying Java process.

ICSSCADAphysical-securitySSRFdeserializationremote-code-executioncritical-infrastructureCISA-advisory

Johnson Controls C-CURE 9000 and victor application server products contain three vulnerabilities, including a critical SSRF flaw (CVSS 9.6) in victor Web and a .NET deserialization-related SSRF issue enabling unauthenticated remote code execution on the application server. Successful exploitation could allow attackers with adjacent network access to compromise physical access control and video security systems, including connected client workstations used by security personnel.

agent-relevantai-agentschatgptworkspace-agentsphishingprivilege-escalationopenaillm-security

Security researchers at Zenity Labs disclosed a critical vulnerability, dubbed AgentForger, in OpenAI's ChatGPT Workspace Agents that could allow an attacker to use a single phishing link to covertly create, authorize, and deploy a rogue autonomous AI agent inside a victim organization. OpenAI patched the issue as of June 8, but the flaw highlights significant risks in agent authorization and deployment workflows within enterprise AI platforms.

active-directoryadcsprivilege-escalationkerberosdcsyncdomain-controllercredential-theftagent-relevant

Security researchers H0j3n and Aniq Fakhrul disclosed Certighost, an exploit chain allowing low-privileged Active Directory users to request a certificate impersonating a Domain Controller. The resulting Kerberos credential inherits directory replication rights, enabling attackers to perform DCSync and extract the krbtgt secret, effectively achieving full domain compromise.

agent-relevantmcprcedefault-credentialshost-header-bypassai-agent-infrastructureunauthenticated-accesschild-process-injection

9router versions up to 0.4.59 contain a chained vulnerability allowing a remote, unauthenticated attacker to gain full control of the host system. By logging in with a hardcoded default password, spoofing the Host header to bypass local-only network restrictions, and registering a malicious MCP plugin, an attacker can achieve arbitrary code execution. This is fixed in version 0.4.60 and should be patched immediately given the ease of exploitation and severity.

path-traversalrceunauthenticatedllm-servingh2oGPTagent-relevantapi-key-exposure

h2oGPT through version 0.2.1 contains an unauthenticated path traversal vulnerability in its OpenAI-compatible files API that allows attackers to read, write, and delete arbitrary files on the host. Because the default API key is empty and the bearer token is used unsanitized as a path component, attackers can bypass authentication entirely and achieve remote code execution by overwriting startup hooks or application-loaded files.

zimbrazero-dayaptrussiaemail-compromise2fa-bypasscredential-theftespionageagent-relevant

A Russian state-sponsored espionage group exploited an unpatched zero-day vulnerability in Zimbra's webmail client to conduct a months-long mail collection campaign against Western targets. The exploit required no user interaction beyond opening a malicious email, and enabled theft of 90 days of mail history, full address book contents, browser-saved passwords, and 2FA recovery codes. NSA, CISA, and partner agencies have issued a joint advisory on the campaign.

oracleldapdirectory-serviceunauthenticated-rceidentity-infrastructureagent-relevant

A maximum-severity vulnerability (CVSS 10.0) exists in Oracle Unified Directory's OUD Core component, allowing an unauthenticated attacker with network access via LDAP to fully compromise the directory service. The vulnerability's scope change indicates successful exploitation can impact additional connected products and systems beyond OUD itself.

oracleaccess-managementauthentication-bypassunauthenticated-rcecritical-infrastructureidentity-provideragent-relevant

A maximum-severity (CVSS 10.0) vulnerability in Oracle Access Manager's Authentication Engine allows unauthenticated, network-based attackers to fully compromise the identity and access management system. The flaw has a scope change, meaning successful exploitation can cascade to impact other integrated applications and services relying on OAM for authentication.

oracleaccess-managerfusion-middlewareunauthenticated-rceauthentication-bypassidentity-managementagent-relevant

A critical unauthenticated vulnerability (CVE-2026-60355) in Oracle Access Manager's Authentication Engine allows remote attackers to fully compromise the identity and access management system over HTTP with no credentials required. Given the CVSS 9.8 score and full confidentiality, integrity, and availability impact, successful exploitation could grant attackers complete control over enterprise authentication infrastructure. Organizations using Oracle Access Manager for SSO or identity federation are at severe risk of large-scale account takeover and downstream system compromise.

oracleaccess-managerauthentication-bypassscope-changeidentity-providerssocritical-infrastructureagent-relevant

A critical vulnerability (CVSS 9.9) in Oracle Access Manager's Authentication Engine allows a low-privileged attacker with only network access via HTTP to fully compromise the identity and access management system. Due to a scope change, successful exploitation can impact additional connected products beyond Oracle Access Manager itself, making this a high-priority patching target for any organization relying on Oracle Fusion Middleware for SSO and access control.