Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 400 threats

os-command-injectionrouteriotremote-code-executionpublic-exploitcgilinksys

A critical OS command injection vulnerability exists in the Linksys RE7000 2.0.15 firmware, affecting the PingTest handler in /cgi-bin/json.cgi. The flaw allows unauthenticated remote attackers to execute arbitrary commands via crafted pingTestIp, pingTestPktSize, or pingTestTimes parameters. Public exploit code is available, significantly increasing the likelihood of mass exploitation against exposed devices.

iotcommand-injectionindustrial-control-systemsadvantechnode-redremote-code-executionpublic-exploit

A critical command injection vulnerability affects multiple Advantech WISE-6610 industrial cellular gateway models running firmware 1.2.1_20251110, exploitable remotely via the Node-RED Library's nodered_lib_apply function. Public exploit code is available, significantly increasing the likelihood of active exploitation against exposed industrial and IoT gateway deployments. Advantech has released a patched firmware version (1.2.4_20260821) to address the flaw.

iotcommand-injectiontendaremote-code-executioncameraunauthenticated

A critical remote OS command injection vulnerability has been identified in Tenda CP3 (firmware 27.5.57.101), affecting the CAutoAddWifi::ThreadProc function within the Kylin component. The flaw allows an unauthenticated remote attacker to execute arbitrary OS commands on the device, with a maximum CVSS score of 10.0. This vulnerability poses a severe risk to networks relying on affected Tenda devices for connectivity or camera/IoT functions.

iotcommand-injectiontendarouter-vulnerabilityremote-exploitunauthenticated

A critical remote OS command injection vulnerability has been identified in the Tenda CP3 (firmware 27.5.57.101) within the Network Configuration Management component. The flaw resides in the sub_2F77E8 function of Apis/system.c and can be exploited remotely without requiring physical access, potentially granting attackers full device compromise.

RCEpre-authenticationRMMCISA-KEVcode-injectionsupply-chain-riskMSPagent-relevant

N-able N-central, a widely used remote monitoring and management (RMM) platform, contains a static code injection vulnerability enabling pre-authentication remote code execution. This flaw is listed in CISA's Known Exploited Vulnerabilities catalog with an aggressive remediation deadline, indicating active exploitation in the wild. Because N-central is deployed by MSPs to manage large fleets of downstream client endpoints, successful exploitation could grant attackers a foothold across many organizations simultaneously.

adobemagentoe-commercetemplate-injectionremote-code-executioncisa-kevserver-side-template-injection

A critical server-side template injection vulnerability affecting Adobe Commerce and Magento Open Source has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild. The flaw allows attackers to inject malicious template elements that are improperly neutralized, resulting in arbitrary code execution on affected servers. Organizations running Adobe Commerce or Magento storefronts must patch by the CISA-mandated due date of September 11, 2026.

magentoadobe-commercezero-daybackdoorlinuxecommerceweb-shell

A zero-day vulnerability named 'StyleSmuggler' affecting all versions of Magento and Adobe Commerce is being actively exploited in the wild to deploy a Linux backdoor on compromised servers. The flaw appears to allow attackers to smuggle malicious code through style/template processing, granting persistent unauthorized access to e-commerce infrastructure.

broken-access-controlsession-hijackingcredential-exposureunauthenticated-accessvideo-platformCVE-2026-86190

A critical broken access control flaw in WWBN AVideo's videoViewsInfo endpoints allows unauthenticated attackers to retrieve full user records—including password hashes, recovery tokens, and live session identifiers—by simply supplying a hash parameter. This enables session hijacking of any user, including administrators, and mass exposure of viewer PII, making full platform takeover trivial for a remote, unauthenticated attacker.

path-traversalunauthenticated-rcefile-uploadauthentication-bypasscve-2026-86189avideoweb-applicationagent-relevant

A critical unauthenticated path traversal vulnerability in WWBN AVideo's notify.ffmpeg.json.php allows attackers to write arbitrary files to the application root and subdirectories via the avideoRelativePath parameter. Combined with a token replay flaw where notifyCode ciphertext is decrypted but never validated, attackers can fully bypass authentication, likely leading to remote code execution via webshell upload.

authentication-bypassunauthenticated-rcedashboardcve-2026-86184misconfigurationagent-relevant

Lara Dashboard versions prior to 1.3.0 contain a critical authentication bypass in the screenshot-login route, allowing unauthenticated attackers to fully authenticate as any registered user when the application is not running in production mode. This can lead to complete administrative takeover, including database access and arbitrary code execution via the module installer.

agent-relevantrceunauthenticatedcontainer-escapeai-agent-frameworkroot-accessexposed-service

AutoAgent, an AI agent framework, contains a critical unauthenticated RCE vulnerability in its TCP server component that binds to all network interfaces and executes attacker-supplied commands as root inside the container. Successful exploitation grants attackers full command execution and access to bind-mounted host workspace directories, enabling lateral movement and host compromise.

agent-relevantrceauthentication-bypasscuaai-agent-infrastructurecontainer-escapeunauthenticated-access

Cua computer-server versions before 0.3.42 contain a critical authentication bypass triggered when the CONTAINER_NAME environment variable is unset, causing the service to bind to all network interfaces without requiring authentication. This exposes a TCP port 8000 service that allows unauthenticated attackers to execute arbitrary shell commands, read/write arbitrary files, and open interactive PTY shells, granting full remote control of the host or container.

sql-injectionrceunauthenticatedweb-shellibmpre-authagent-relevant

IBM Operational Decision Manager contains an unauthenticated SQL injection vulnerability that allows attackers to execute arbitrary SQL statements and abuse database functionality to write a web shell into the application web root. This results in full remote code execution without requiring any credentials, making it a critical risk for exposed instances.

command-injectionrceffmpegai-modelagent-relevantunsanitized-inputvideo-generation

SadTalker, a popular AI-driven talking-head video generation tool, contains a critical OS command injection vulnerability in its video muxing pipeline. Attacker-controlled audio filenames are passed unescaped into ffmpeg shell commands, allowing arbitrary code execution during video generation with no authentication required. Given the tool's widespread use in AI content pipelines and agent-driven media generation workflows, this represents a high-impact RCE vector.

agent-relevantllmfastchatssrfauthentication-bypassrce-adjacentapi-key-exposurerag-pipelineinference-infrastructure

A critical unauthenticated vulnerability in FastChat's /register_worker endpoint allows attackers to register rogue model workers and hijack traffic intended for legitimate LLM backends. This enables interception of prompts, images, and responses, as well as SSRF-based internal network reconnaissance across the worker mesh.

agent-relevantRCEunauthenticated-accessfile-writeai-frameworkorchestration-tooltman-designer

CVE-2026-85688 is a critical unauthenticated arbitrary file read/write vulnerability in TEN Framework 0.11.71's TMAN Designer, exposed via the /api/designer/v1/file-content API endpoints. Attackers can exploit this to read sensitive files or write malicious payloads to system paths, achieving remote code execution through mechanisms like SSH authorized_keys injection, cron job manipulation, or malicious graph file execution.

path-traversalunauthenticatedrce-potentialfile-writeagent-relevantfastapidocument-processing

Marker, a document processing/conversion tool through version 2.0.0, contains an unauthenticated path traversal vulnerability in its FastAPI /marker/upload endpoint due to improper sanitization of the file.filename parameter. Attackers can exploit this to write arbitrary files anywhere on the filesystem or delete existing files, potentially leading to remote code execution, denial of service, or data destruction without requiring any authentication.

vmwarevirtualizationprivilege-escalationvm-escapebroadcompatch-nowagent-relevant

Broadcom has patched a critical integer-overflow vulnerability in VMware Workstation and Fusion (CVE-2026-59346, CVSS 9.3) that allows a local attacker with elevated privileges inside a virtual machine to execute arbitrary code on the host system. Organizations running affected VMware products should apply the update immediately, as successful exploitation could lead to full host compromise from within a guest VM.

magentoadobe-commerceecommerceunauthenticated-rcebackdoorzero-dayweb-skimming

Attackers are actively exploiting an unpatched zero-day vulnerability, dubbed StyleSmuggler, in Magento Open Source and Adobe Commerce to achieve unauthenticated remote code execution on store servers. Discovered by Sansec, exploitation began September 4, 2026, with attackers installing backdoors to maintain persistent access to compromised e-commerce platforms. No official patch is currently available, leaving all unmitigated instances exposed.

ICSVPNprivilege-escalationCRLF-injectionCWE-93CWE-306remote-code-execution

IXON VPN Client versions before 1.4.7 contain a critical CRLF injection vulnerability that allows an unauthenticated local attacker to inject configuration directives consumed by a privileged subprocess, resulting in remote code execution as root or SYSTEM. The flaw persists silently across restarts with no visible behavioral change, making detection difficult. IXON has released a patched client and blocks connections from vulnerable versions at the cloud/API level as a compensating control.