Threat Library
Agent-to-agent threats first — conventional coverage one click away.
Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10
Showing 20 of 400 threats
GitLab disclosed a maximum-severity (CVSS 10.0) path traversal vulnerability in the repository commits API that allows unauthenticated attackers to read arbitrary files on the GitLab server. Active in-the-wild probing was observed within hours of public disclosure, indicating high urgency for patching. Organizations should treat this as an actively exploited zero-day and prioritize immediate remediation.
A critical heap-based buffer overflow exists in the JPEG decoder within libimagecodec.quram.so, a native image codec library used in Samsung devices prior to the September 2026 SMR release. Remote attackers can exploit this flaw via a maliciously crafted JPEG image to achieve arbitrary code execution, potentially without user interaction depending on the delivery vector (e.g., MMS, messaging apps, or web content auto-rendering images). This affects a widely deployed component across the Samsung Android ecosystem.
A critical heap-based buffer overflow exists in the DNG image decoder within libimagecodec.quram.so, a native image codec library used on Samsung mobile devices. Remote attackers can trigger the flaw by delivering a malicious DNG/image file, potentially achieving arbitrary code execution without user interaction depending on the delivery vector (e.g., MMS, messaging apps, or web content). The vulnerability carries a maximum-severity CVSS score of 9.8 and was patched in the September 2026 Samsung Mobile Security Release.
CVE-2026-85706 is an unauthenticated path traversal vulnerability in GitLab Community Edition and Enterprise Edition that allows attackers to read arbitrary files on affected servers via the repository commits API. This flaw has been added to CISA's Known Exploited Vulnerabilities catalog with an aggressive remediation deadline of September 14, 2026, indicating confirmed active exploitation in the wild.
CVE-2026-42016 is an actively exploited incorrect authorization vulnerability in JFrog Artifactory, added to CISA's Known Exploited Vulnerabilities catalog with a remediation deadline of September 25, 2026. The flaw arises from token validation logic checking only signature and issuer rather than scope, enabling attackers with a valid but improperly-scoped token to escalate privileges within the artifact repository.
ConnectWise ScreenConnect contains a privilege management and authorization flaw that allows an attacker to perform unauthorized file transfer and code execution during active remote sessions without host confirmation. This vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild, and requires urgent patching given its short remediation window (due date only three days after addition).
A critical OS Command Injection vulnerability in Adobe Campaign Classic (ACC) allows arbitrary code execution in the context of the current user without any user interaction, and has a maximum CVSS score of 10.0 with a changed scope. This flaw poses severe risk to organizations running ACC for marketing automation, as unauthenticated or minimally-privileged attackers could gain full control of affected servers.
CVE-2026-69854 is a critical improper authentication vulnerability in Spring Cloud Azure that allows an unauthorized network attacker to escalate privileges without valid credentials. Given a CVSS score of 9.0, successful exploitation could grant attackers elevated access to Azure-integrated services and downstream resources managed by affected applications.
CVE-2026-69431 is a critical heap-based buffer overflow vulnerability in the Telnet Client that allows an unauthorized remote attacker to execute arbitrary code over the network without authentication. With a CVSS score of 9.8, this vulnerability poses severe risk to any system with the vulnerable Telnet client installed or enabled. Organizations should treat this as a high-priority patching target given the low complexity of exploitation and lack of required privileges.
Netis NX10 routers running firmware V4.0.1.5808 or V3.0.0.4142 expose the administrator password to unauthenticated attackers via the sysinfo action in the web management interface. Attackers can retrieve this credential without a valid session and replay it against the login handler to gain full administrative control of the device, effectively enabling complete device takeover with a CVSS score of 9.8.
A previously undocumented exploit kit dubbed BlueMoon, which chains multiple Windows and Chrome vulnerabilities, has been observed in use by at least four distinct espionage-motivated threat clusters within a single week, including China-aligned APT31. The rapid, near-simultaneous deployment across separate groups suggests shared tooling infrastructure, a leaked/sold exploit chain, or a common third-party broker supplying nation-state actors.
Cisco has confirmed active exploitation of CVE-2026-20079, a maximum-severity authentication bypass vulnerability in Secure Firewall Management Center (FMC) software. Attackers exploiting this flaw could gain unauthorized administrative access to centralized firewall management infrastructure, potentially compromising network-wide security controls. Organizations running affected FMC versions should treat this as an urgent patching priority.
CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, affecting Fortinet products, Citrix NetScaler, Google Chromium V8, and Cisco Firewall Management Center. These vulnerabilities include authentication bypass and memory corruption flaws that grant attackers significant post-exploitation control, and federal agencies are required under BOD 26-04 to remediate them on an accelerated timeline.
A critical stack-based buffer overflow vulnerability affects the udhcpcd component of D-Link DIR-895L routers running firmware A1_102b07, specifically within the sendOffer/sendACK functions of serverpacket.c. The flaw is exploitable only by attackers on the local network, but a public exploit is available, significantly increasing the risk of exploitation. Successful exploitation could allow attackers to crash the device or achieve remote code execution on the router.
MISP versions up to 2.5.45 contain SSRF vulnerabilities in feed retrieval and TAXII discovery functionality due to insufficient validation of outbound HTTP redirects and DNS resolution. Attackers controlling a malicious or compromised feed/TAXII source can redirect MISP's outbound requests to internal network resources or forward configured authentication credentials to attacker-controlled hosts. This is especially dangerous given MISP's role as a trusted threat-intelligence hub often integrated into automated security and enrichment pipelines.
Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management contain a critical authentication bypass vulnerability that allows unauthenticated remote attackers to execute scripts and gain root access to the underlying operating system. This flaw has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog with a compressed remediation window, indicating active or imminent exploitation in the wild. Organizations using Cisco FMC to manage firewall infrastructure face full compromise risk of their central security management plane.
CVE-2026-87491 is an out-of-bounds write vulnerability in Google Chromium's V8 JavaScript engine that allows remote code execution within the browser sandbox via a crafted HTML page. The flaw is included in CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild, and affects all Chromium-based browsers including Chrome, Edge, and Opera. Organizations must patch by the September 23, 2026 CISA deadline to mitigate risk of remote compromise.
CVE-2025-25249 is a heap-based buffer overflow affecting FortiOS, FortiSwitchManager, and FortiSASE that allows remote code execution via specially crafted packets. The vulnerability has been added to CISA's Known Exploited Vulnerabilities catalog with a short remediation window, indicating active exploitation in the wild.
A maximum-severity (CVSS 10.0) pre-authentication remote code execution vulnerability in N-able N-central, a widely used remote monitoring and management (RMM) platform, is being actively exploited in the wild. CISA has added CVE-2026-86218 to its Known Exploited Vulnerabilities catalog, mandating FCEB agencies remediate by September 11, 2026, underscoring the urgency and severity of the flaw.
Knowns versions prior to 0.30.0 expose an unauthenticated management API on all network interfaces by default, with no password set on fresh installs. Attackers can leverage the exposed /api/tunnel/start endpoint to publicly republish the internal management API, gaining full administrative access without credentials. This flaw is trivially exploitable via internet-wide scanning and poses a critical risk to any deployment that has not been manually hardened.