Threat Library
Agent-to-agent threats first — conventional coverage one click away.
Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10
Showing 20 of 307 threats
GitLab disclosed a maximum-severity (CVSS 10.0) path traversal vulnerability in the repository commits API that allows unauthenticated attackers to read arbitrary files on the GitLab server. Active in-the-wild probing was observed within hours of public disclosure, indicating high urgency for patching. Organizations should treat this as an actively exploited zero-day and prioritize immediate remediation.
CISA has added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog affecting JFrog Artifactory and ConnectWise ScreenConnect. These flaws involve improper authentication and authorization controls that could allow attackers to bypass access restrictions and gain unauthorized privileged access. FCEB agencies must remediate under BOD 26-04, and CISA urges all organizations to prioritize patching given confirmed in-the-wild exploitation.
A critical heap-based buffer overflow exists in the JPEG decoder within libimagecodec.quram.so, a native image codec library used in Samsung devices prior to the September 2026 SMR release. Remote attackers can exploit this flaw via a maliciously crafted JPEG image to achieve arbitrary code execution, potentially without user interaction depending on the delivery vector (e.g., MMS, messaging apps, or web content auto-rendering images). This affects a widely deployed component across the Samsung Android ecosystem.
A critical heap-based buffer overflow exists in the DNG image decoder within libimagecodec.quram.so, a native image codec library used on Samsung mobile devices. Remote attackers can trigger the flaw by delivering a malicious DNG/image file, potentially achieving arbitrary code execution without user interaction depending on the delivery vector (e.g., MMS, messaging apps, or web content). The vulnerability carries a maximum-severity CVSS score of 9.8 and was patched in the September 2026 Samsung Mobile Security Release.
CVE-2026-85706 is an unauthenticated path traversal vulnerability in GitLab Community Edition and Enterprise Edition that allows attackers to read arbitrary files on affected servers via the repository commits API. This flaw has been added to CISA's Known Exploited Vulnerabilities catalog with an aggressive remediation deadline of September 14, 2026, indicating confirmed active exploitation in the wild.
JFrog Artifactory contains an improper authentication flaw that can return an internal anonymous-user access token to unauthenticated callers even when anonymous access has been explicitly disabled. This could allow attackers to access sensitive repository resources without valid credentials, undermining the intended access control model of the artifact repository. CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild.
CVE-2026-42016 is an actively exploited incorrect authorization vulnerability in JFrog Artifactory, added to CISA's Known Exploited Vulnerabilities catalog with a remediation deadline of September 25, 2026. The flaw arises from token validation logic checking only signature and issuer rather than scope, enabling attackers with a valid but improperly-scoped token to escalate privileges within the artifact repository.
CVE-2026-69431 is a critical heap-based buffer overflow vulnerability in the Telnet Client that allows an unauthorized remote attacker to execute arbitrary code over the network without authentication. With a CVSS score of 9.8, this vulnerability poses severe risk to any system with the vulnerable Telnet client installed or enabled. Organizations should treat this as a high-priority patching target given the low complexity of exploitation and lack of required privileges.
CVE-2026-67277 is a missing authentication vulnerability in MikroTik RouterOS's btest (bandwidth test) service, allowing unauthenticated attackers to trigger kernel memory disclosure and denial of service. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild, with a short remediation window (added 2026-09-10, due 2026-09-13).
CVE-2026-86060 is an actively exploited vulnerability in MikroTik RouterOS involving improper neutralization of argument delimiters in command processing, allowing attackers to manipulate the trusted RouterOS policy mask and escalate privileges. CISA has added this flaw to its Known Exploited Vulnerabilities (KEV) catalog with a short remediation window, indicating confirmed in-the-wild exploitation.
A previously undocumented exploit kit dubbed BlueMoon, which chains multiple Windows and Chrome vulnerabilities, has been observed in use by at least four distinct espionage-motivated threat clusters within a single week, including China-aligned APT31. The rapid, near-simultaneous deployment across separate groups suggests shared tooling infrastructure, a leaked/sold exploit chain, or a common third-party broker supplying nation-state actors.
Cisco has confirmed active exploitation of CVE-2026-20079, a maximum-severity authentication bypass vulnerability in Secure Firewall Management Center (FMC) software. Attackers exploiting this flaw could gain unauthorized administrative access to centralized firewall management infrastructure, potentially compromising network-wide security controls. Organizations running affected FMC versions should treat this as an urgent patching priority.
CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, affecting Fortinet products, Citrix NetScaler, Google Chromium V8, and Cisco Firewall Management Center. These vulnerabilities include authentication bypass and memory corruption flaws that grant attackers significant post-exploitation control, and federal agencies are required under BOD 26-04 to remediate them on an accelerated timeline.
A critical stack-based buffer overflow vulnerability affects the udhcpcd component of D-Link DIR-895L routers running firmware A1_102b07, specifically within the sendOffer/sendACK functions of serverpacket.c. The flaw is exploitable only by attackers on the local network, but a public exploit is available, significantly increasing the risk of exploitation. Successful exploitation could allow attackers to crash the device or achieve remote code execution on the router.
CVE-2026-80131 is a path traversal vulnerability in Dell SCG 5.0 Appliance and Application prior to versions 5.36.00.16 and 5.36.00.00 respectively. An unauthenticated remote attacker can exploit this flaw to escape restricted directories and achieve remote code execution on the affected system.
Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management contain a critical authentication bypass vulnerability that allows unauthenticated remote attackers to execute scripts and gain root access to the underlying operating system. This flaw has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog with a compressed remediation window, indicating active or imminent exploitation in the wild. Organizations using Cisco FMC to manage firewall infrastructure face full compromise risk of their central security management plane.
CVE-2026-87491 is an out-of-bounds write vulnerability in Google Chromium's V8 JavaScript engine that allows remote code execution within the browser sandbox via a crafted HTML page. The flaw is included in CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild, and affects all Chromium-based browsers including Chrome, Edge, and Opera. Organizations must patch by the September 23, 2026 CISA deadline to mitigate risk of remote compromise.
CVE-2025-25249 is a heap-based buffer overflow affecting FortiOS, FortiSwitchManager, and FortiSASE that allows remote code execution via specially crafted packets. The vulnerability has been added to CISA's Known Exploited Vulnerabilities catalog with a short remediation window, indicating active exploitation in the wild.
A maximum-severity (CVSS 10.0) pre-authentication remote code execution vulnerability in N-able N-central, a widely used remote monitoring and management (RMM) platform, is being actively exploited in the wild. CISA has added CVE-2026-86218 to its Known Exploited Vulnerabilities catalog, mandating FCEB agencies remediate by September 11, 2026, underscoring the urgency and severity of the flaw.
CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog affecting Adobe Commerce/Magento, Microsoft Windows, and N-able N-central, all confirmed under active exploitation. FCEB agencies must remediate per BOD 26-04, and CISA urges all organizations to prioritize patching given the demonstrated real-world attack activity.