Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 889 threats

os-command-injectionrouteriotremote-code-executionpublic-exploitcgilinksys

A critical OS command injection vulnerability exists in the Linksys RE7000 2.0.15 firmware, affecting the PingTest handler in /cgi-bin/json.cgi. The flaw allows unauthenticated remote attackers to execute arbitrary commands via crafted pingTestIp, pingTestPktSize, or pingTestTimes parameters. Public exploit code is available, significantly increasing the likelihood of mass exploitation against exposed devices.

iotcommand-injectionindustrial-control-systemsadvantechnode-redremote-code-executionpublic-exploit

A critical command injection vulnerability affects multiple Advantech WISE-6610 industrial cellular gateway models running firmware 1.2.1_20251110, exploitable remotely via the Node-RED Library's nodered_lib_apply function. Public exploit code is available, significantly increasing the likelihood of active exploitation against exposed industrial and IoT gateway deployments. Advantech has released a patched firmware version (1.2.4_20260821) to address the flaw.

iotcommand-injectiontendaremote-code-executioncameraunauthenticated

A critical remote OS command injection vulnerability has been identified in Tenda CP3 (firmware 27.5.57.101), affecting the CAutoAddWifi::ThreadProc function within the Kylin component. The flaw allows an unauthenticated remote attacker to execute arbitrary OS commands on the device, with a maximum CVSS score of 10.0. This vulnerability poses a severe risk to networks relying on affected Tenda devices for connectivity or camera/IoT functions.

iotcommand-injectiontendarouter-vulnerabilityremote-exploitunauthenticated

A critical remote OS command injection vulnerability has been identified in the Tenda CP3 (firmware 27.5.57.101) within the Network Configuration Management component. The flaw resides in the sub_2F77E8 function of Apis/system.c and can be exploited remotely without requiring physical access, potentially granting attackers full device compromise.

windowsprivilege-escalationlocal-exploitcisa-kevalpcheap-overflowagent-relevant

CVE-2026-85880 is a heap-based buffer overflow in Microsoft Windows Advanced Local Procedure Call (ALPC) that enables local privilege escalation. The vulnerability has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation in the wild, with a remediation deadline of September 22, 2026.

RCEpre-authenticationRMMCISA-KEVcode-injectionsupply-chain-riskMSPagent-relevant

N-able N-central, a widely used remote monitoring and management (RMM) platform, contains a static code injection vulnerability enabling pre-authentication remote code execution. This flaw is listed in CISA's Known Exploited Vulnerabilities catalog with an aggressive remediation deadline, indicating active exploitation in the wild. Because N-central is deployed by MSPs to manage large fleets of downstream client endpoints, successful exploitation could grant attackers a foothold across many organizations simultaneously.

windowsprivilege-escalationlocal-exploitCISA-KEVwindows-update-stacklink-followingagent-relevant

CVE-2026-81963 is a local privilege escalation vulnerability in the Microsoft Windows Update Stack caused by improper handling of file system links, allowing a local attacker to gain SYSTEM-level privileges. The flaw has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild, with a remediation deadline of September 22, 2026.

adobemagentoe-commercetemplate-injectionremote-code-executioncisa-kevserver-side-template-injection

A critical server-side template injection vulnerability affecting Adobe Commerce and Magento Open Source has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild. The flaw allows attackers to inject malicious template elements that are improperly neutralized, resulting in arbitrary code execution on affected servers. Organizations running Adobe Commerce or Magento storefronts must patch by the CISA-mandated due date of September 11, 2026.

chrome-zero-dayrouter-exploitationsupply-chain-attackcredential-theftqr-code-phishingnetwork-management-protocol-abuseagent-relevant

This weekly recap covers multiple active threats including a Chrome 0-day, router hijacking campaigns, and a notable supply chain attack against the Coder platform that resulted in credential theft. Attackers also demonstrated a novel phishing technique using text-rendered QR codes to bypass email image-blocking protections, and abused a network management protocol for malicious purposes.

vishingsocial-engineeringMicrosoft 365AitMtoken-theftSaaSexecutive-targetingextortionresidential-proxyagent-relevant

A threat cluster is targeting executives (directors, VPs, senior staff) at organizations using Microsoft 365 and other SaaS platforms through IT help desk vishing calls, adversary-in-the-middle (AitM) session token theft, and sign-ins routed through residential proxy networks to evade geolocation-based detection. Stolen credentials and session tokens are used for data exfiltration followed by extortion demands. The campaign leverages human trust in IT support workflows rather than software exploits, making it effective against organizations with strong technical controls but weaker identity-verification processes.

post-exploitationbrowser-hijackingchromiumbackdooragent-relevantcredential-theftpersistence

PEEP is a post-compromise toolkit that disguises itself as a bookmarks extension for Chrome and Edge, requiring prior administrative or code execution access to deploy. It forges Chromium's Secure Preferences file to bypass Web Store validation and user consent prompts, effectively turning the browser into a persistent backdoor capable of executing host commands.

data-breachedtechthird-party-riskbusiness-intelligence-toolPII-exposure

Online mathematics learning platform Mathspace disclosed a data breach affecting over 1 million students, staff, and parents after attackers compromised its Metabase internal reporting system. The breach exposed personal data likely including names, emails, and academic records tied to a widely used education platform. No technical details on the intrusion vector into Metabase have been disclosed.

phishing-as-a-serviceAiTMMFA-bypassMicrosoft 365credential-theftbusiness-email-compromiseagent-relevant

BigBear 2.0, a phishing-as-a-service (PhaaS) platform, has been used to compromise 258 organizations and steal over 5,000 Microsoft 365 credentials by bypassing multi-factor authentication via adversary-in-the-middle (AiTM) reverse-proxy techniques. The kit lowers the barrier to entry for large-scale credential phishing campaigns and has demonstrated broad reach across sectors relying on Microsoft 365 for identity and collaboration.

magentoadobe-commercezero-daybackdoorlinuxecommerceweb-shell

A zero-day vulnerability named 'StyleSmuggler' affecting all versions of Magento and Adobe Commerce is being actively exploited in the wild to deploy a Linux backdoor on compromised servers. The flaw appears to allow attackers to smuggle malicious code through style/template processing, granting persistent unauthorized access to e-commerce infrastructure.

ICSSCADAsession-hijackinginsufficient-entropycritical-infrastructureenergy-sectorSchneider-ElectricCWE-331

A high-severity vulnerability (CVE-2026-4827) affecting numerous Schneider Electric Easergy, EcoStruxure, PowerLogic, and Saitel protection relays, RTUs, gateways, and SCADA/HMI software stems from insufficient entropy in session token generation. An attacker on the network could exploit weak session-management protections to hijack sessions and perform unauthorized operations on critical electrical grid control and protection devices.

broken-access-controlsession-hijackingcredential-exposureunauthenticated-accessvideo-platformCVE-2026-86190

A critical broken access control flaw in WWBN AVideo's videoViewsInfo endpoints allows unauthenticated attackers to retrieve full user records—including password hashes, recovery tokens, and live session identifiers—by simply supplying a hash parameter. This enables session hijacking of any user, including administrators, and mass exposure of viewer PII, making full platform takeover trivial for a remote, unauthenticated attacker.

path-traversalunauthenticated-rcefile-uploadauthentication-bypasscve-2026-86189avideoweb-applicationagent-relevant

A critical unauthenticated path traversal vulnerability in WWBN AVideo's notify.ffmpeg.json.php allows attackers to write arbitrary files to the application root and subdirectories via the avideoRelativePath parameter. Combined with a token replay flaw where notifyCode ciphertext is decrypted but never validated, attackers can fully bypass authentication, likely leading to remote code execution via webshell upload.

authentication-bypassunauthenticated-rcedashboardcve-2026-86184misconfigurationagent-relevant

Lara Dashboard versions prior to 1.3.0 contain a critical authentication bypass in the screenshot-login route, allowing unauthenticated attackers to fully authenticate as any registered user when the application is not running in production mode. This can lead to complete administrative takeover, including database access and arbitrary code execution via the module installer.

agent-relevantrceunauthenticatedcontainer-escapeai-agent-frameworkroot-accessexposed-service

AutoAgent, an AI agent framework, contains a critical unauthenticated RCE vulnerability in its TCP server component that binds to all network interfaces and executes attacker-supplied commands as root inside the container. Successful exploitation grants attackers full command execution and access to bind-mounted host workspace directories, enabling lateral movement and host compromise.

agent-relevantrceauthentication-bypasscuaai-agent-infrastructurecontainer-escapeunauthenticated-access

Cua computer-server versions before 0.3.42 contain a critical authentication bypass triggered when the CONTAINER_NAME environment variable is unset, causing the service to bind to all network interfaces without requiring authentication. This exposes a TCP port 8000 service that allows unauthenticated attackers to execute arbitrary shell commands, read/write arbitrary files, and open interactive PTY shells, granting full remote control of the host or container.