Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 918 threats

data-breachthird-party-risksupply-chainretaillogisticsPII-exposure

Pokémon Center notified customers in the UK and Germany of a data breach involving their personal and order information, caused by a compromise at third-party logistics provider CEVA Logistics. The breach resulted in exposure of customer data and led to the cancellation of some pending orders, highlighting risks inherent in outsourced fulfillment operations.

credential-theftcloud-securitydata-breachazureidentity-compromiseagent-relevant

A threat actor claims to be selling 3.6 million employee records allegedly exfiltrated from Microsoft Azure environments belonging to multiple Fortune 500 companies. The intrusion reportedly stemmed from compromised credentials rather than a platform vulnerability, highlighting ongoing risks around identity and access management in cloud tenants. The claim remains unverified but poses significant exposure risk if confirmed.

CISAKEVcode-injectionrayagent-relevantML-infrastructurefederal-mandate

CISA added CVE-2025-62593, a code injection vulnerability in Ray-Project Ray, to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. Federal agencies are required under BOD 26-04 to remediate this vulnerability on a prioritized basis due to its potential to grant full control of affected assets.

routerauthentication-bypassunpatchedpublic-exploitIoTnetwork-infrastructureno-vendor-response

A critical authentication bypass vulnerability exists in the httpcon_check_session_url function of EFM ipTIME A3004T routers (firmware 14.19.0), allowing remote attackers to circumvent session validation without credentials. A working exploit is publicly available and the vendor has not responded to disclosure, leaving affected devices permanently exposed.

routerfirmwarebuffer-overflowrceiotunpatchedpublic-exploitedimax

A critical unauthenticated remote code execution vulnerability exists in Edimax EW-7478APC routers running firmware 1.04, caused by a stack-based buffer overflow in the formWanTcpipSetup CGI handler. Public exploit code is available and the vendor has not responded to disclosure, meaning no patch is expected. Organizations using this device on network edges face significant risk of full device compromise and pivoting into internal networks.

wordpressplugin-vulnerabilityprivilege-escalationauthorization-bypasscve-2026-18432

The Frontend Admin by DynamiApps WordPress plugin (versions up to 3.29.9) contains a critical privilege escalation vulnerability caused by a flawed authorization check that can be bypassed with a non-numeric user ID value. Attackers, in some configurations even unauthenticated, can exploit this to gain administrator access by hijacking the default admin account's password or email. Given the 9.8 CVSS score and low exploitation complexity, this vulnerability poses a severe risk to any WordPress site running the affected plugin.

wordpressplugin-vulnerabilityunauthenticated-rcefile-uploadcmsweb-application-security

The ProSolution WP Client WordPress plugin (versions up to 2.0.10) contains a critical unauthenticated arbitrary file upload vulnerability that allows remote attackers to achieve remote code execution. A publicly exposed nonce combined with insufficient filename validation lets attackers bypass access controls and upload executable files directly to the server.

routeriotauthentication-bypassunauthenticated-accesspublic-exploitnetwork-perimeter

A critical improper authentication vulnerability has been identified in the httpd component of Tenda AC10 routers running firmware 16.03.10.09_multi_TDE01, specifically within the R7WebsSecurityHandler function. The flaw allows a remote, unauthenticated attacker to bypass authentication controls, and a public exploit is already available, significantly raising the likelihood of active exploitation.

agent-relevantraycode-injectionrceml-infrastructuredistributed-computingbrowser-exploitCISA-KEV

CVE-2025-62593 is a code injection vulnerability in Ray-Project Ray, a widely used distributed computing framework for scaling AI/ML and Python workloads, that can lead to remote code execution. The flaw is exploitable via Firefox and Safari when developers interact with Ray's tooling, and it has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild.

ddosmessagingavailabilitythreemanetwork-attack

Threema, a secure messaging service, suffered multiple large-scale DDoS attacks that caused severe disruptions to user communications. The attacks appear focused on service availability rather than data compromise, with no evidence of encryption bypass or user data exposure reported.

outageavailabilityanthropicclaudeagent-relevant

Anthropic's Claude AI service experienced a major outage affecting multiple services, with users reporting login failures and degraded performance. This is an availability incident rather than a confirmed malicious cyberattack, though the root cause has not been publicly disclosed.

data-breachcryptocurrencyhardware-walletPII-exposuredark-web-sale

Cryptocurrency hardware wallet vendor SafePal disclosed a data breach affecting approximately 39,798 customers after an application flaw was exploited to exfiltrate customer order information. A threat actor is now advertising the stolen data for sale on underground forums, raising risk of targeted phishing and social engineering against affected customers.

ICSCISA-advisorySiemensfile-parsingmemory-corruptionout-of-bounds-readout-of-bounds-writeuse-after-freecritical-manufacturinglocal-code-execution

Siemens Solid Edge SE2025 and SE2026 contain seven high-severity memory corruption vulnerabilities (CVSS 7.8) triggered when parsing specially crafted PAR, PSM, or DFT files, which could allow an attacker to crash the application or achieve arbitrary code execution in the context of the current process. Exploitation requires a user to open a malicious file, making this a local-vector, user-interaction-required threat rather than a remotely exploitable one. Siemens has released patched versions (SE2025 V225.0.15+ and SE2026 V226.0.7+) and organizations should update promptly.

siyuanpdf-annotationrceelectronnode-jsstored-xssagent-relevantknowledge-managementrag-pipeline

SiYuan, an open-source Electron-based note-taking and knowledge management application, fails to sanitize annotation fields written via the setFileAnnotation endpoint prior to v3.7.4. This allows an attacker to embed malicious markup that executes as script with full Node.js privileges when a victim opens an annotated PDF, enabling complete host compromise.

wordpressplugin-vulnerabilityfile-deletionrceunauthenticatedcms-security

The Link Library plugin for WordPress (versions up to 7.9.4) contains an arbitrary file deletion vulnerability caused by insufficient path validation in the ll_delete_link_fields function. When the 'Delete local file on link deletion' option is enabled, unauthenticated attackers can submit malicious links that, once deleted by an administrator during routine moderation, trigger deletion of critical files such as wp-config.php, potentially leading to full remote code execution.

wordpressplugin-vulnerabilityprivilege-escalationauthorization-bypasscmsweb-application-security

The Pods – Custom Content Types and Fields WordPress plugin (versions up to 3.3.9) contains a critical authorization bypass flaw that allows unauthenticated attackers to escalate privileges to Administrator or reset any user's password, including the site owner's. This enables complete site takeover and has been assigned a CVSS score of 9.8.

wordpressplugin-vulnerabilityaccount-takeoverunauthenticatedprivilege-escalationweb-application

The TrueBooker WordPress plugin (versions up to 1.2.6) contains a critical account takeover vulnerability due to an insecure AJAX handler that allows unauthenticated attackers to change any user's email address, including administrators. Attackers can chain this with WordPress's native password reset flow to fully hijack accounts, including full site administrator access.

wordpressplugin-vulnerabilityauthentication-bypasstype-confusionprivilege-escalationcmsweb-application

The User Profile Builder plugin for WordPress (versions up to 3.16.4) contains a critical authentication bypass vulnerability caused by improper error handling during user registration. An unauthenticated attacker can exploit a type confusion flaw to obtain an autologin nonce bound to user ID 1, effectively logging in as the site's Administrator and achieving full site takeover.

microsoft-defenderpatch-bypassprivilege-escalationwindowsSYSTEM-accesszero-dayproof-of-conceptagent-relevant

A researcher known as Chaotic Eclipse released a public proof-of-concept called ShieldBreak that bypasses Microsoft's patch for CVE-2026-50656 (RoguePlanet), a Windows Defender vulnerability. The PoC reportedly grants SYSTEM-level access, meaning organizations that applied the original patch may still be exposed to full local privilege escalation.

SAPRCEactive-exploitationenterprise-softwarecommerce-platform

A maximum-severity remote code execution vulnerability in SAP Commerce Cloud, patched only three days prior, is already being actively exploited in the wild according to threat intelligence firm Defused. Organizations running unpatched instances face immediate risk of full system compromise, making rapid patching or mitigation critical.