Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 400 threats

VoIPSQL-injectionRCEreverse-shellSangomaSwitchvoxunauthenticatedexploitation-in-the-wild

Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection flaw in the Sangoma Switchvox VoIP platform, to achieve remote code execution and deploy reverse shells. The vulnerability allows attackers to gain full control of vulnerable systems without credentials, posing a serious risk to organizations running exposed Switchvox deployments.

kubernetesmulti-clusterrceroot-privilege-escalationipsecconfig-injectionagent-relevant

A critical vulnerability in Submariner's cert-auth mode allows a malicious cluster to inject arbitrary ipsec.conf directives via an unsanitized CableName field in a Custom Resource Definition. This enables remote code execution as root on gateway nodes through leftupdown hook abuse, fully compromising the multi-cluster networking layer.

sonicwallcommand-injectionrceremote-accessvpn-appliancecisa-kevedge-device

CVE-2026-83549 is an OS command injection vulnerability in SonicWall SMA1000 Appliances that allows an authenticated remote attacker with administrative privileges to execute arbitrary OS commands, leading to full remote code execution. CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog with an unusually short three-day remediation window, indicating active exploitation or imminent risk. Organizations using SMA1000 appliances for secure remote access should prioritize immediate patching.

SonicWallSSRFCISA-KEVremote-accessVPN-applianceunauthenticated-exploit

CVE-2026-83548 is a server-side request forgery vulnerability in SonicWall SMA1000 Appliances that allows a remote, unauthenticated attacker to reach sensitive internal functionality and perform unauthorized operations. CISA has added this CVE to its Known Exploited Vulnerabilities catalog with a compressed remediation window, indicating active or imminent exploitation in the wild. Organizations using SMA1000 for secure remote access should treat this as an urgent patching priority.

sql-injectionunauthenticated-rcevoipcisa-kevpostgresqlnetwork-appliance

Sangoma Switchvox, a VoIP PBX platform, contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request. This flaw has been added to CISA's Known Exploited Vulnerabilities catalog with an extremely tight remediation window, indicating active exploitation in the wild. Successful exploitation can lead to database compromise and remote code execution on the underlying host.

kestraos-command-injectionunauthenticated-rceworkflow-orchestrationcisa-kevagent-relevant

Kestra OSS, an open-source workflow and orchestration platform, contains an OS command injection vulnerability (CVE-2026-49869) that allows unauthenticated remote attackers to create and execute arbitrary workflows without credentials. This vulnerability has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild, with a remediation due date of September 5, 2026.

artifactoryauthentication-bypasssupply-chainci-cddevopsagent-relevantexploitation-in-the-wild

Threat actors are actively exploiting a critical authentication bypass vulnerability (CVE-2026-82329, CVSS 9.8) in JFrog Artifactory just days after public disclosure, allowing attackers to mint administrative access tokens under default configurations. This provides full administrative control over artifact repositories, enabling malicious package injection, credential theft, and downstream supply-chain compromise.

authentication-bypassproxmoxvirtualizationprivilege-escalationagent-relevanteol-softwareapi-vulnerability

A critical authentication bypass vulnerability in Proxmox Virtual Environment allows unauthenticated attackers to log in as any enabled user, including root@pam, by supplying an arbitrary value in the tfa-challenge parameter during API login. This completely circumvents password verification and two-factor authentication, granting full administrative control over the hypervisor. All affected versions are end of life and will not receive official patches, making immediate upgrade the only viable remediation path.

kubernetespolicy-bypassprivilege-escalationcontainer-securityadmission-controlleragent-relevant

A logic flaw in Kyverno's policy exception handling (v1.9.0–v1.12.7) allows attackers to bypass enforce-mode security policies by crafting resource names that match a less restrictive PolicyException. This can be exploited to circumvent critical controls such as hostPath volume restrictions, potentially enabling container breakout or node compromise.

wordpressprivilege-escalationaccount-takeoverauthentication-bypasscmsweb-application

The Nokri Job Board WordPress theme (versions up to 1.6.6) contains a critical authentication bypass vulnerability that allows unauthenticated attackers to take over any user account, including administrators. The flaw stems from improper validation of password reset tokens, enabling attackers to reset passwords using empty token values matched against empty or unset user meta fields.

path-traversaldokploytraefikrceunauthenticatedpublic-exploitagent-relevantself-hosted-paasdevops-tooling

A critical unauthenticated path traversal vulnerability affects Dokploy up to version 0.29.7, specifically in the writeTraefikConfigInPath function used by the Settings component to generate Traefik configuration files. The flaw allows remote attackers to manipulate the path argument to write files outside intended directories, potentially leading to configuration overwrite, service disruption, or remote code execution. A public exploit is available and the vendor has not responded to disclosure, leaving deployments unpatched and exposed.

d-linknasos-command-injectioncginetwork-storagepublicly-disclosedremote-exploitiot

A critical OS command injection vulnerability affects multiple D-Link NAS devices (DNS-320L, DNS-327L, DNS-340L, DNS-345) through the usb_device.cgi CGI handler. The flaw allows unauthenticated remote attackers to execute arbitrary OS commands via the f_ups_ip parameter, and a public exploit is already available, making immediate exploitation highly likely.

iaciamprivilege-escalationcloud-securitypulumiinfrastructure-as-codeagent-relevant

A critical privilege escalation vulnerability in hulumi (versions prior to v1.3.2) allows attackers with access to a documented IAM principal to abuse an overly permissive weekly integration policy. This enables creation of persistent, higher-privilege af-e2e-* roles in sandbox accounts, potentially leading to full account compromise.

iam-misconfigurationoidcawsgithub-actionssupply-chaincicd-securityagent-relevant

A critical flaw in @hulumi/policies before version 1.3.2 allows attackers to craft AWS IAM condition operators (ForAnyValue:StringLike) that evade security guardrails designed to detect overly permissive GitHub Actions OIDC trust policies. This enables attackers to establish stealthy, wildcard-based trust relationships between arbitrary GitHub repositories/workflows and AWS IAM roles, potentially leading to unauthorized cross-account access.

iotrouterbuffer-overflowrcetotolinkpublic-exploitunauthenticated

A critical stack-based buffer overflow vulnerability affects the TOTOLINK NR1800X router firmware, exploitable remotely via the setUploadSetting function without authentication. A public exploit exists, making this an immediate risk for internet-exposed devices.

d-linkrouteriotrcebuffer-overflownetwork-deviceunauthenticatedexploit-published

A critical remote code execution vulnerability exists in D-Link DIR-825M 1.1.8 routers, caused by a stack-based buffer overflow in the LTE Module Firmware Upgrade handler (formLtefotaUpgradeFibocom). An attacker can remotely manipulate the fota_url parameter to trigger the overflow, with a public exploit already available, making this an immediate risk to exposed devices.

buffer-overflowrouteriotremote-code-executionpublic-exploittendaboa-web-server

A critical, publicly disclosed vulnerability affects the Tenda HG10 router (firmware 300001138) via its Boa Web Server admin interface. The flaw allows remote, unauthenticated attackers to trigger a buffer overflow through the destNet parameter in the formIPv6Routing function, potentially leading to full device compromise. With a CVSS score of 10.0 and public exploit code available, active exploitation is highly likely.

PaperCutCISA-KEVRCEunsafe-reflectionchained-exploitprint-managementjava

PaperCut NG/MF is affected by an unsafe reflection vulnerability that allows attackers to manipulate system configuration parameters and execute arbitrary Java bytecode under the security context of the PaperCut server process. This flaw has been added to CISA's Known Exploited Vulnerabilities catalog and can be chained with CVE-2026-81578 to achieve full remote code execution, mirroring the exploitation pattern seen in prior PaperCut attacks used for ransomware and network intrusion.

iotroutermemory-corruptionremote-code-executionpublicly-disclosedtotolink

A critical remotely exploitable memory corruption vulnerability exists in TOTOLINK A720R routers running firmware 4.1.5cu.630_B20250509, affecting the setMacFilterRules function within cstecgi.cgi. The flaw is triggered via manipulation of the 'desc' argument in MAC filtering rules and has been publicly disclosed with exploit details available, increasing the likelihood of active exploitation.

wordpressauthentication-bypassprivilege-escalationplugin-vulnerabilitycms

The MyHome Core plugin for WordPress (versions up to 4.4.5) contains an authentication bypass vulnerability that allows unauthenticated attackers to hijack unconfirmed user accounts, including administrator accounts, under specific configuration conditions. Successful exploitation grants full administrative access to the WordPress site, enabling complete site takeover.