Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 918 threats

IBMDb2Db2 MirrorIBM iauthentication-bypassimproper-input-validationCVE-2026-17182critical-infrastructuredatabase-security

CVE-2026-17182 is a critical authentication bypass vulnerability in IBM Db2 Mirror for i affecting versions 7.4, 7.5, and 7.6, allowing remote attackers to bypass authentication controls due to improper validation of request URI path segments. Exploitation could result in unauthorized access, disclosure, or alteration of sensitive database information without requiring credentials. With a CVSS score of 9.8, this vulnerability poses a severe risk to organizations running affected Db2 Mirror deployments.

path-traversalibm-db2remote-code-executionibm-iunauthenticateddatabase

A critical path traversal vulnerability in IBM Db2 Mirror for i allows remote attackers to write arbitrary files to unintended filesystem locations. With a CVSS score of 9.3, successful exploitation could lead to arbitrary code execution, data corruption, or full system compromise on affected IBM i platforms.

grav-cmsprivilege-escalationapi-key-abusebroken-access-controlcms-vulnerabilityrce-chainagent-relevant

A critical vulnerability in the getgrav/grav-plugin-api plugin (before 1.0.13) allows an attacker holding a minimal-scope API key to mint a new, unscoped super-access API key by submitting an empty scopes array. This bypasses intended scope restrictions and can be chained with configuration write access to achieve full remote code execution on the underlying Grav CMS instance.

path-traversalopenwrtrouter-securityrceprivilege-escalationssh-backdooredge-devicenetwork-infrastructure

A critical path traversal vulnerability in luci-app-openvpn allows authenticated attackers to write arbitrary files outside the intended upload directory, enabling persistent root-level code execution on OpenWrt-based devices. Exploitation involves planting SSH keys in system directories to maintain access across reboots, making this a severe threat to routers and embedded network infrastructure.

path-traversalrceibmunauthenticatedagent-relevant

A critical vulnerability (CVE-2026-17482) in IBM Documentation Offline versions 1.0.0 through 1.4.1 allows remote attackers to execute arbitrary code due to improper control of file paths. With a CVSS score of 9.8, this flaw is likely exploitable without authentication and poses severe risk to any host running the affected software. Organizations should treat this as an urgent patching priority given the potential for full system compromise.

adobecoldfusionrcecommand-injectionprivilege-escalationpatch-tuesdayagent-relevant

Adobe has released patches for multiple critical vulnerabilities affecting ColdFusion, Commerce, and Campaign Classic, including at least one flaw rated a maximum CVSS score of 10.0. Successful exploitation could allow unauthenticated attackers to achieve arbitrary OS command execution and privilege escalation on affected servers.

security-reportbenchmarkdetection-gaplateral-movementbreach-and-attack-simulationdefense-analytics

Picus Labs' Blue Report 2026 analyzed over 338 million attack simulations across production environments in H1 2026, finding that while perimeter/edge defenses have improved significantly, internal detection and containment capabilities have deteriorated. Attackers are increasingly succeeding not through loud, high-signature attacks but through low-noise techniques that evade internal detection once initial defenses are bypassed.

sharepointauthentication-bypasspoc-exploitmicrosofton-premisesrce-riskagent-relevant

Threat actors are actively exploiting CVE-2026-55040, a critical SharePoint authentication bypass vulnerability, following the public release of proof-of-concept code. The flaw, patched in Microsoft's July 2026 Patch Tuesday, stems from weak authentication controls and carries a CVSS score of 9.1, allowing attackers to bypass security controls on unpatched SharePoint servers.

ransomwareEDR-evasionsafe-modedata-exfiltrationakiradouble-extortion

An Akira ransomware affiliate compromised a target network and rebooted a system into Safe Mode with Networking to disable endpoint detection and response (EDR) protections. The attacker successfully exfiltrated data but failed to deploy the encryption payload, resulting in a partial (extortion-only) compromise rather than full ransomware impact.

law-enforcementfraudcall-center-scaminvestment-scamsocial-engineeringtakedown

Ukrainian authorities dismantled 94 fraudulent call centers that were running investment scams and attempting to gain unauthorized access to victims' bank accounts. Millions in cash were seized during the coordinated operation, representing a significant disruption to organized fraud networks operating in the region.

spywaremercenary-spywaremobile-securityiosnation-statesurveillancetargeted-attack

Apple has issued new 'Threat Notification' alerts warning select iPhone users that they have been targeted by mercenary spyware attacks. These notifications, part of Apple's ongoing threat intelligence program, indicate highly targeted, sophisticated attacks typically associated with commercial spyware vendors like NSO Group or Intellexa rather than broad-based malware campaigns.

ICSOTBACnetdenial-of-serviceSiemensbuilding-automationCVE-2026-59693

A denial-of-service vulnerability (CVE-2026-59693) affects Siemens Desigo DXR and PXC building automation controllers. An attacker with adjacent network access can send a malformed BACnet packet to cause the device to stop responding, requiring a manual reset or reboot to restore functionality. Siemens has released firmware updates to remediate the issue.

ICSSiemensprivilege-escalationpath-traversalvulnerabilityCVECISA-advisorylicensing-server

Siemens License Server (SLS) versions prior to 5.1 and 5.3 are affected by two vulnerabilities: an insecure sudoers policy enabling local privilege escalation to root, and a path traversal flaw allowing remote unauthenticated attackers to read arbitrary files. Siemens has released patched versions and CISA has published an advisory recommending immediate updates.

ICSCISA-advisorySiemensout-of-bounds-readfile-parsingCVE-2026-64629critical-manufacturing

Siemens Parasolid, a 3D geometric modeling kernel used in CAD/CAM/CAE software across critical manufacturing, contains an out-of-bounds read vulnerability (CVE-2026-64629) triggered when parsing malformed X_T files. Successful exploitation could crash the application or allow arbitrary code execution in the context of the current process. Siemens has released patched versions (V38.0.235 and V38.1.230) and users are advised to update.

wordpressplugin-backdoorsupply-chainrcepersistenceweb-shell

A tampered build of Ninja Tables Pro 5.2.11 was distributed through a decommissioned update server, embedding a malicious PHP updater component that grants attackers persistent backdoor access. The compromised plugin creates a passwordless admin account, drops web shells in mu-plugins and uploads directories, and registers scheduled tasks that survive plugin removal, making remediation difficult. Organizations running affected WordPress instances face full site takeover risk, including any hosted applications, APIs, or backend services running on the same host.

wordpresssupply-chainbackdoorplugin-compromiseagent-relevantpersistencerce

A tampered build of Fluent Forms Pro 6.2.7 distributed via a decommissioned update server injects a malicious PHP file that installs a backdoor REST API endpoint, a passwordless administrator account, and persistent scheduled tasks. This constitutes a supply-chain compromise capable of full site takeover, with persistence mechanisms designed to survive plugin removal.

rsyncaccess-control-bypassip-spoofingunauthenticatednetwork-protocolagent-relevant

A critical vulnerability in rsync daemon versions prior to 3.5.0 allows unauthenticated remote attackers to spoof source IP addresses via a crafted PROXY protocol header, bypassing IP-based hosts allow/deny access controls. This enables attackers who can reach the rsync daemon port to gain unauthorized access to file shares that would otherwise be restricted by network-level trust policies.

IBM-iprivilege-escalationauthorization-flawenterprise-serverinsider-threat

A critical vulnerability in IBM i affects versions 7.3 through 7.6, allowing a remote authenticated attacker to escalate privileges through improper authorization checks on high-authority threads. With a CVSS score of 9.6, this flaw could enable an attacker with low-level access to gain full administrative control over the system.

IBM-iprivilege-escalationuncontrolled-search-patharbitrary-code-executionauthenticated-attackenterprise-server

A critical vulnerability in IBM i versions 7.3 through 7.6 allows a remote authenticated attacker to execute arbitrary code by exploiting an uncontrolled search path element. With a CVSS score of 9.9, this flaw could enable low-privileged users to escalate to full system compromise on affected IBM Power Systems servers.

AI-securityLLMreasoning-APIsession-replaycredential-exposureAPI-key-leakageagent-relevantOpenAIAnthropicGoogle

Researchers disclosed a flaw in how OpenAI, Anthropic, and Google encode and carry hidden chain-of-thought reasoning between API calls, allowing encrypted reasoning objects from one session to be replayed into another session. This cross-session replay allowed weaker models to decode or expose internal reasoning content from stronger models, including sensitive data such as API keys and passwords captured in session logs.