Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 918 threats

ICSOTindustrial-control-systemsunauthenticated-RCEnode-redsiemensedge-deviceagent-relevant

A critical vulnerability (CVSS 10.0) in Siemens SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED allows unauthenticated remote attackers to execute arbitrary code with maximum privileges via the exposed Node-RED HTTP interface. Attackers can craft malicious flows to invoke system command nodes, achieving full device compromise with no authentication required.

sql-injectionunauthenticated-rceweb-applicationdatabase-compromisetravel-industry

CVE-2026-19425 is a critical unauthenticated SQL injection vulnerability in Win Men International's Travel Agency Management System, allowing remote attackers to fully compromise backend databases without credentials. With a CVSS score of 9.8, exploitation could lead to complete data exfiltration, modification, or destruction, posing severe risk to organizations relying on this platform for customer and booking data.

sql-injectionmetabaseunauthenticated-rcedata-exfiltrationcisa-kevagent-relevant

Metabase, a widely used open-source business intelligence and analytics platform, contains an unauthenticated SQL injection vulnerability that can grant attackers full administrative access to the application. CISA has added this CVE to its Known Exploited Vulnerabilities catalog with a short remediation window, indicating active exploitation in the wild. Successful exploitation exposes connected database credentials and any data accessible through those connections.

windowsprivilege-escalationuse-after-freekernel-driverCISA-KEVagent-relevant

CVE-2026-68820 is a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys) that allows a locally authenticated attacker to escalate privileges to SYSTEM. It has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild, with federal agencies required to remediate by August 25, 2026.

ciscoasaftdfirewalldoscisa-kevnetwork-infrastructureunauthenticated-rce-risk

A heap inspection vulnerability in Cisco Secure Firewall ASA and FTD allows an unauthenticated, remote attacker to trigger an unexpected device reload, causing a denial-of-service condition. CISA has added this CVE to its Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild, with a mandated remediation due date of August 14, 2026.

weekly-recapsupply-chainzero-dayMCPagent-relevantrouter-backdoorAI-security

This week's roundup highlights a Metabase zero-day, supply-chain attacks targeting Model Context Protocol (MCP) tooling used in AI agent ecosystems, and backdoors found in consumer/enterprise routers. The report is an aggregated digest rather than a single incident, but the MCP supply-chain angle is directly relevant to organizations deploying AI agents and LLM tool-use frameworks.

ransomwarechina-linkedstorm-1175n-centralrmm-exploitationdouble-extortion

Microsoft has identified Storm-1175, a financially motivated China-linked threat actor, deploying a new ransomware strain called StormEncryptor, marking a shift from their prior use of Medusa ransomware. Initial access is suspected to involve exploitation of a flaw in N-central, a remote monitoring and management (RMM) platform commonly used by MSPs to administer client endpoints and infrastructure.

vendor-contentnot-a-threatapplication-securitydevsecopsAI-generated-codeinformational

This item is promotional content advertising a webinar about managing security risks introduced by AI-accelerated software development, rather than an active threat, vulnerability, or campaign. It highlights a legitimate industry concern: as AI coding assistants increase code output volume, security teams may struggle to keep pace with vulnerability review, dependency management, and risk prioritization.

product-launchai-security-toolingvulnerability-researchpentestingnot-a-threatagent-relevant

This is a product announcement rather than an active threat: OpenAI has released 'GPT-5.6 Cyber,' a specialized model for vulnerability research, penetration testing, incident response, and remediation, gated to approved users. The release has security implications for both defenders and potential misuse by threat actors if access controls are bypassed or credentials are compromised.

wordpresssupply-chainplugin-compromiseadmin-takeoverweb-security

A threat actor compromised the upstream infrastructure of BdThemes, a premium WordPress plugin developer, and tampered with a remote JSON feed served to site administrators. This modified feed was used to silently create rogue administrator accounts on affected WordPress installations, granting attackers persistent backend access.

OTICScritical-infrastructureenergyAPNcellular-networkremote-accessindustrial-control-systems

Hackers breached the operational technology (OT) network of a small Polish heat-and-power plant serving approximately 50,000 residents by exploiting a private Access Point Name (APN) used for remote cellular connectivity. The incident, disclosed as having occurred the prior year, highlights how insufficiently secured private cellular networks can serve as an overlooked pathway into critical infrastructure control systems.

SAPcommand-injectionRCEmanufacturinginput-validationcritical-infrastructure

A critical command injection vulnerability affects SAP Manufacturing Integration and Intelligence (MII), allowing a high-privileged attacker to submit crafted input that is insufficiently validated, leading to arbitrary OS command execution. Exploitation could fully compromise confidentiality, integrity, and availability of the affected system. Organizations running SAP MII in manufacturing or industrial environments should prioritize patching.

sapnetweavermemory-corruptionunauthenticated-rcedoserpcritical-infrastructure

A critical unauthenticated vulnerability (CVE-2026-34265) affects SAP NetWeaver Application Server ABAP, stemming from logical errors in DIAG protocol parsing that lead to memory corruption. With a CVSS score of 9.8, attackers can remotely disclose sensitive information or crash affected systems without any authentication, posing severe risk to organizations running SAP ERP environments.

kubernetesauthentication-bypassprivilege-escalationmaasmulti-tenancyagent-relevantai-infrastructureapi-security

CVE-2026-14450 is a critical authentication bypass vulnerability in the Model-as-a-Service (MaaS) API layer fronted by Kuadrant's AuthPolicy gateway. Any pod within the affected Kubernetes cluster can forge the X-MaaS-Username and X-MaaS-Group HTTP headers, which are trusted verbatim without first-party verification, enabling full cross-tenant privilege escalation. This allows attackers to mint ServiceAccount tokens in other tenants' namespaces, revoke arbitrary API keys, and exfiltrate model access configuration data.

routercommand-injectiontelnetfirmwarerceiotnetwork-device

A critical command injection vulnerability exists in the TelnetSSH configuration function of MSI Radix AXE6600 router firmware v781521, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This flaw could be leveraged to fully compromise home and small-office network infrastructure, enabling traffic interception, lateral movement, or botnet recruitment.

routercommand-injectionrcesshfirmwarenetwork-deviceunauthenticated

A critical command injection vulnerability exists in the TelnetSSH configuration function of MSI Radix AXE6600 routers running firmware v781521, allowing remote attackers to execute arbitrary commands with root privileges. Given the CVSS score of 9.8, this flaw is likely remotely exploitable without authentication, making affected devices prime targets for botnet recruitment, traffic interception, or use as network pivot points.

CISA-KEVcommand-injectionload-balancernetwork-applianceactive-exploitationedge-device

A critical command injection vulnerability in Progress Kemp LoadMaster, tracked as CVE-2026-8037 (CVSS 9.6), has been added to CISA's Known Exploited Vulnerabilities catalog after 792 reported exploitation attempts in the wild. The flaw allows attackers to achieve arbitrary command execution on affected load balancer appliances, posing severe risk to organizations relying on this infrastructure for traffic management.

RMMexploitation-in-the-wildMSPsupply-chain-riskremote-monitoringhotfixagent-relevant

N-able has released a second hotfix for its N-central Remote Monitoring and Management (RMM) platform after observing threat actors actively exploiting a recently disclosed vulnerability and evolving their attack techniques to persist on managed endpoints. The vendor is expanding protections beyond the initial patch, indicating attackers reaching into managed customer environments through the compromised RMM infrastructure.

prompt-injectionagent-relevantAI-securitydata-exfiltrationAtlassianindirect-prompt-injectionRAGLLM-tool-use

Security researchers demonstrated that Atlassian's Rovo AI assistant can be manipulated via attacker-controlled content (e.g., uploaded files or embedded instructions) to collect Jira and Confluence data accessible to a signed-in user and exfiltrate it to an external server. Two independent research teams found separate exploitation paths; only one has been confirmed remediated by Atlassian.

sharepointgovernmentdata-breachaccount-compromiseon-premises

Switzerland's Federal Office of Information Technology disclosed that attackers exploited vulnerabilities in on-premises Microsoft SharePoint servers to compromise roughly 200 government accounts. The incident highlights ongoing risks tied to unpatched or exposed SharePoint deployments within critical government infrastructure.