Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 408 threats

sharepointprivilege-escalationcisa-kevunauthenticatedon-premisesexploited-in-the-wild

CVE-2026-56164 is a missing authentication for critical function vulnerability in Microsoft SharePoint Server that allows an unauthorized, remote attacker to elevate privileges over the network. CISA has added this CVE to its Known Exploited Vulnerabilities (KEV) catalog with an aggressive three-day remediation deadline, indicating active exploitation in the wild. Organizations running on-premises SharePoint Server deployments should treat this as an urgent patching priority.

cve-2026-61498command-injectionunauthenticated-rceweb-applicationvitec-flamingoroot-privilege-escalation

A critical unauthenticated OS command injection vulnerability exists in Vitec Flamingo 4.12.2's graph generation endpoint, allowing remote attackers to execute arbitrary commands with root privileges. The flaw stems from unsanitized GET parameters being passed directly into shell execution functions, combined with insecure passwordless sudo configuration on the web server. Given the CVSS score of 9.8 and lack of authentication requirement, this is highly likely to be mass-exploited by opportunistic attackers and botnets once a public PoC emerges.

gawkinteger-overflowheap-corruptionmemory-corruptionlinuxgnu-utilsdenial-of-serviceagent-relevant

A critical integer overflow vulnerability in gawk's builtin.c allows attackers to trigger memory exhaustion and corrupt heap metadata with attacker-controlled bytes, affecting versions 5.4.0 and below. Given gawk's ubiquity as a core text-processing utility on Linux/Unix systems, this vulnerability poses risk to any system, script, or automated pipeline that invokes gawk for data transformation.

os-command-injectionrouteriotunauthenticated-rcefastcgipublic-exploit

A critical unauthenticated OS command injection vulnerability affects the Comfast CF-WR631AX V3 router firmware up to version 2.7.0.8, exploitable remotely via the system_wl_upload_pic_file function in the webmgnt FastCGI backend. A public exploit exists, and the vendor has not responded to disclosure, leaving affected devices permanently exposed to compromise.

agent-relevantarbitrary-file-writeRAG-pipelineLLM-toolingdockerpath-traversaldenial-of-servicecrawl4ai

Crawl4AI, a popular web-crawling library used to feed content into LLM pipelines and RAG systems, contains a critical arbitrary file write vulnerability in its Docker API server's /screenshot and /pdf endpoints. Unauthenticated or low-privilege attackers can supply crafted output_path values to write files anywhere the service account can access, potentially overwriting critical server files and causing denial of service or further compromise.

npmsupply-chaininfostealerrust-malwarepreinstall-hookagent-relevantjavascriptnodejs

The popular jscrambler npm package was compromised, with a malicious 8.14.0 release published on July 11, 2026 that executes a Rust-based infostealer via a preinstall hook during npm install. The attack drops platform-specific native binaries for Windows, macOS, and Linux, meaning any developer or CI/CD system installing this version is automatically compromised. Socket detected the malicious release within six minutes of publication, but organizations that auto-updated or pulled the package before detection remain at risk.

ICSOTEV-chargingOCPPcritical-infrastructureauthentication-bypassdenial-of-servicetransportation-sector

Hydro-Québec's Le Circuit Electrique EV charging station backend contains three vulnerabilities—an unauthenticated websocket endpoint, lack of authentication attempt throttling, and insufficient session/connection controls—that could allow privilege escalation or denial-of-service attacks. The most severe flaw (CVSS 9.8) permits unauthenticated connections to the charging station's OCPP websocket, enabling attackers to potentially impersonate charging stations or escalate privileges. Hydro-Québec has mitigated most affected stations by disabling OCPP or adding authentication.

agent-relevantprompt-injectionLLM-tool-abuseRCEarbitrary-file-writeprivilege-escalationAI-agent-framework

PraisonAI, an AI agent framework, contains a critical vulnerability in its AICoder component that allows attackers to abuse LLM tool-calling functionality to write files anywhere on the filesystem and execute arbitrary commands with root privileges. Exploitation can occur via malicious prompt injection through the chat interface, requiring no prior authentication or system access in many deployments. Given the CVSS score of 9.9, this represents a full system compromise vector for any organization running affected PraisonAI versions.

sql-injectioncql-injectionpraisonairagvector-databaseagent-relevantcve-2026-60090

PraisonAI versions prior to 4.6.78 contain an unvalidated dimension parameter in the PGVector and Cassandra knowledge-store create_collection() functions, allowing attackers to inject arbitrary SQL/CQL into the generated DDL statement. Any caller able to influence collection creation—including downstream API consumers or agent orchestration logic—can execute destructive or data-exfiltrating database commands, resulting in a critical 9.8 CVSS-rated vulnerability.

wordpressplugin-vulnerabilityauthentication-bypassaccount-takeoveroauthotp-brute-forceadmin-takeovercms-security

The miniOrange Social Login and Register plugin for WordPress (versions up to 7.7.0) contains a critical authentication bypass allowing unauthenticated attackers to take over any account, including administrators. The flaw stems from unvalidated email input during OAuth profile completion combined with a weak, offline-crackable OTP scheme, enabling full site compromise. Given the 9.8 CVSS score and low attack complexity, mass exploitation against internet-facing WordPress sites is likely once a working exploit circulates.

path-traversalrceidedeveloper-toolsjetbrainsagent-relevantsupply-chain-risk

A critical path traversal vulnerability in JetBrains IntelliJ IDEA allows remote code execution through manipulation of project workspace ID handling. With a CVSS score of 9.6, this flaw could allow attackers to execute arbitrary code on developer workstations, potentially via malicious project files or shared workspace configurations.

ssrfxxexsdcloud-metadatakubernetescredential-theftllm-guardrailsagent-relevant

A critical SSRF vulnerability in the guardrails-detectors component allows remote attackers to submit malicious XSD schemas that trigger out-of-band requests to internal services. Exploitation can expose cloud metadata credentials, Kubernetes API tokens, MinIO endpoints, and local files such as service account tokens, enabling further lateral movement and privilege escalation.

sharefileprogress-softwarestorage-zone-controllerfile-transferactive-exploitationvendor-advisoryenterprise-storage

Progress Software has urgently instructed ShareFile customers to shut down Windows servers hosting Storage Zone Controllers in response to a credible external security threat. The company has proactively disabled access to affected accounts while investigating with internal and external security teams, though no CVE or technical exploit details have been publicly disclosed yet. This mirrors past Progress Software incidents (e.g., MOVEit) where file-transfer products were mass-exploited via zero-days.

wordpressfile-uploadrceunauthenticatedplugin-vulnerabilityweb-application

The Instant Appointment plugin for WordPress (versions up to 1.2) contains a critical arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files, potentially leading to remote code execution. Given the CVSS score of 9.8 and lack of authentication requirement, this vulnerability is highly likely to be targeted by automated exploitation once public details are available.

sql-injectionapi-gatewayibmunauthenticatedapi-connectagent-relevant

IBM API Connect versions 10.0.8.0-10.0.8.9 and 12.1.0.0-12.1.0.3 contain an unauthenticated SQL injection vulnerability in the password reset functionality, rated critical with a CVSS score of 9.1. An attacker can exploit this remotely without credentials to access, modify, or exfiltrate backend database contents.

cvecisa-kevfile-uploadrceweb-applicationwordpress-pluginunauthenticated

iCagenda, a WordPress event management plugin, contains an unrestricted file upload vulnerability in its file attachment feature that allows attackers to upload malicious PHP files. This can lead to full remote code execution on the underlying web server. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild.

CISA-KEVunauthenticated-RCEfile-uploadplugin-vulnerabilityweb-applicationCMSJoomlaWordPresspatch-priority

Balbooa Forms, a form-builder component/plugin, contains an unrestricted file upload vulnerability allowing unauthenticated attackers to upload malicious executable files and achieve remote code execution. The flaw has been added to CISA's Known Exploited Vulnerabilities catalog with a compressed three-day remediation window, indicating active exploitation in the wild.

ICSOTPLCarbitrary-file-writeremote-code-executionpath-traversalcritical-infrastructureend-of-life-software

OpenPLC v3's legacy web UI program-upload workflow allows an authenticated user to write arbitrary files anywhere on the filesystem due to unsanitized handling of the prog_file parameter. This flaw can be escalated to full native code execution as the OpenPLC runtime user by planting a malicious C++ source file that gets auto-compiled during normal program build operations, posing a severe risk to industrial control environments in Critical Manufacturing, Energy, Transportation, and Water/Wastewater sectors.

rceunauthenticatedwebuiterminal-apiagent-relevantpty-hijackcritical-infrastructure-exposure

Hermes WebUI versions before 0.51.788 expose an embedded terminal API that lacks authentication, allowing remote attackers to open a PTY session and execute arbitrary shell commands with only four HTTP requests. Given the CVSS score of 9.8 and the trivial exploitation path, this vulnerability poses a severe risk to any internet-facing or internally exposed Hermes deployment.

authentication-bypassssrfapi-key-theftoauth-abuseagent-relevantllm-provider-hijackcloud-metadata-exposurewebui-vulnerability

A critical authentication bypass in Hermes WebUI (versions before 0.51.307) allows unauthenticated attackers to spoof local-origin IP restrictions using a forged X-Forwarded-For header, gaining access to onboarding endpoints intended only for local administrators. This enables server-side request forgery against internal infrastructure, hijacking of LLM provider configurations and API keys, and abuse of OAuth device-code flows to mint persistent access tokens. Given the CVSS score of 9.1, this vulnerability poses severe risk to any deployment exposing Hermes WebUI to untrusted networks.