Conventional Threats Watchlist

Browse by attack type

Showing 181–200 of 804 threats, newest first

wordpressplugin-vulnerabilityphp-object-injectionunauthenticateddeserializationpop-chainweb-application-security

The WS Form LITE WordPress plugin (versions up to 1.10.80) contains a PHP Object Injection vulnerability caused by insecure deserialization of untrusted form submission meta values. While no exploitable POP (Property-Oriented Programming) chain exists within the plugin itself, the presence of a vulnerable POP chain in any other installed plugin or theme could enable unauthenticated attackers to achieve file deletion, data exfiltration, or remote code execution.

Updated Aug 23, 2026 · CVSS 9.8

iotrouterbuffer-overflowremote-code-executiontrendnetcgiunauthenticatedpublic-exploit

A critical stack-based buffer overflow vulnerability exists in TRENDnet TEW-821DAP routers (firmware 2.2.01b05) within the NTP Timezone Configuration Handler's uci_safe_get function. The flaw is remotely exploitable without authentication via manipulated CGI parameters, and a public exploit is already available, making immediate exploitation likely.

Updated Aug 23, 2026 · CVSS 10

wordpressssrfplugin-vulnerabilityaccount-takeovermailguncve-2026-78003unauthenticated

The Mailgun for WordPress plugin (versions up to 2.2.0) contains an unauthenticated SSRF vulnerability caused by insufficient input validation in the add_list() function. Attackers can leverage this flaw to make authenticated requests to any Mailgun API endpoint using the site's stored API key, enabling creation of email-forwarding rules that intercept password reset emails and result in full administrator account takeover.

Updated Aug 23, 2026 · CVSS 9.8

IBMAIXPowerVMVIOSprivilege-escalationRCEunixcritical-infrastructure

A critical vulnerability (CVE-2026-17145) affects IBM AIX versions 7.2 and 7.3, as well as IBM PowerVM VIOS 4.1, allowing a remote, unauthenticated attacker to execute arbitrary code due to improper privilege management. With a CVSS score of 9.8, this flaw poses severe risk to enterprises running IBM Power systems, potentially enabling full system compromise. Organizations using these platforms for critical workloads, including hosted virtualized environments, should prioritize patching.

Updated Aug 23, 2026 · CVSS 9.8

kubernetesmulti-clustersubmarinerlighthouseprivilege-escalationopenshiftcluster-federationagent-relevant

A critical vulnerability in Lighthouse (Submariner's multi-cluster service discovery component) allows an attacker who has compromised a spoke cluster to inject malicious EndpointSlices and ServiceImports into arbitrary namespaces on peer clusters, including sensitive system namespaces. This can lead to traffic hijacking, privilege escalation, and broader compromise of federated Kubernetes/OpenShift environments.

Updated Aug 23, 2026 · CVSS 9.9

androidiotautomotivead-fraudproxy-botnetsupply-chainfirmwaredownloader

Kaspersky discovered a malware family targeting Android-based vehicle head unit firmware developed by DoFun, which propagates via built-in firmware updaters. The malware deploys a multi-stage downloader used to conduct ad fraud and enlist infected devices into a proxy botnet.

Updated Aug 22, 2026

windowslolbinlolbin-driverkernel-exploitdefenderedr-evasionliving-off-the-landprivilege-escalationagent-relevant

Check Point Research disclosed a technique abusing Microsoft Defender's own legitimately signed boot-time remediation driver (BTR.sys) to perform arbitrary kernel-level file and registry operations on Windows systems, including deletion of security software at boot. Because BTR.sys is Microsoft-signed and no external or malicious driver is introduced, the technique bypasses driver-signature enforcement and many endpoint protections, affecting Windows 7 through Windows 11 25H2.

Updated Aug 22, 2026

npmsupply-chainlinuxbackdoormalicious-packageai-c2agent-relevantnodejsdeveloper-tools

Researchers identified 14 trojanized npm packages disguised as calendar and streak-tracking utilities that covertly deploy an AI-powered Linux backdoor called RedC2 4.0. The malware extracts and executes a bundled binary as a detached background process, giving attackers persistent, AI-assisted command-and-control capability on infected hosts.

Updated Aug 22, 2026

windows-updatecompatibility-issuergb-softwarenon-securitybug

Microsoft has identified that games crashing or failing to launch after installing the August 2026 Windows updates may be caused by conflicts with RGB lighting peripheral software rather than a security vulnerability. This is a functional compatibility bug affecting gaming systems, not a cybersecurity threat.

Updated Aug 22, 2026

awscredential-exposurecloud-securitysecrets-managementapi-keysagent-relevant

Over 9,300 AWS access keys publicly exposed between August 2022 and August 2026 remain active and valid, granting attackers full control over corporate AWS accounts. These leaked credentials likely originate from hardcoded secrets in public repositories, misconfigured applications, or logging errors, posing an ongoing risk of account takeover, data theft, and resource abuse.

Updated Aug 22, 2026

malwarephishingcredential-theftmicrosoft-teamsloadersocial-engineering

A new malware loader named SynkLoader is being distributed through Microsoft Teams phishing campaigns, using a fake lock screen overlay to harvest user credentials. The campaign leverages the trust employees place in Teams notifications and internal communication tools to deliver the loader and steal login credentials.

Updated Aug 22, 2026

CISAKEVZimbraOS-command-injectionactive-exploitationemail-serverfederal-agenciesagent-relevant

CISA has added CVE-2026-73570, an OS command injection vulnerability in Zimbra Collaboration Suite (ZCS), to its Known Exploited Vulnerabilities Catalog based on confirmed active exploitation. Federal Civilian Executive Branch agencies are required under BOD 26-04 to remediate this vulnerability on an expedited timeline, and CISA urges all organizations to prioritize patching.

Updated Aug 22, 2026

kubernetesmulti-clustersubmarinernetwork-hijacktraffic-interceptioncloud-nativeagent-relevant

A critical vulnerability in Submariner, a multi-cluster Kubernetes networking tool, allows a malicious spoke cluster to advertise arbitrary and unvalidated network subnets to peer clusters. This enables the attacker to hijack traffic intended for legitimate destinations, rerouting it through an attacker-controlled tunnel for interception, disruption, or man-in-the-middle attacks across the federated cluster mesh.

Updated Aug 22, 2026 · CVSS 9.9

IBMAIXPowerVMVIOSfile-overwriteinput-validationremote-attack

A critical vulnerability (CVE-2026-16926) affects IBM AIX 7.2, 7.3, and PowerVM VIOS 4.1, allowing remote attackers to overwrite arbitrary files due to improper input sanitization. With a CVSS score of 9.1, this flaw poses significant risk to enterprise Unix/virtualization environments running on IBM Power hardware.

Updated Aug 22, 2026 · CVSS 9.1

iotrouterbuffer-overflowrcepublic-exploitnetwork-devicefirmware

A critical stack-based buffer overflow exists in the mycli binary of TRENDnet TEW-755AP wireless access points, triggered by unsanitized input in the SSID parameter. The vulnerability is remotely exploitable and a public exploit is available, making it an immediate risk for exposed devices. CVSS 9.9 reflects the potential for full device compromise without authentication.

Updated Aug 22, 2026 · CVSS 9.9

kubernetesrbacprivilege-escalationcluster-adminopenshiftoperatoragent-relevant

The search-v2-operator, commonly deployed in Kubernetes/OpenShift environments (e.g., Red Hat Advanced Cluster Management), is provisioned with a ClusterRole granting effectively cluster-admin level permissions. This over-privileged configuration allows the operator or any workload/service account leveraging it to impersonate users, forge RBAC bindings, approve CSRs, and manage ManifestWork objects, enabling full cluster takeover.

Updated Aug 22, 2026 · CVSS 9.9

iotrouterbuffer-overflowrcepublic-exploitnvramcgi

A critical stack-based buffer overflow vulnerability exists in TRENDnet TEW-823DRU routers (firmware 1.1.02b01) due to unsafe use of strcpy on the wan_l2tp_password parameter in /cgi-bin/wan.cgi. The flaw is remotely exploitable without complex prerequisites, and public exploit code is already available, making it an immediate risk for internet-exposed or compromised-network devices.

Updated Aug 22, 2026 · CVSS 9.9

zimbracommand-injectionunauthenticated-rcesmtpemail-servercisa-kevagent-relevant

CVE-2026-73570 is an unauthenticated OS command injection vulnerability in Synacor Zimbra Collaboration Suite that can be triggered via specially crafted SMTP requests, leading to arbitrary command execution as the Zimbra user. CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog with an unusually short remediation window, indicating active exploitation in the wild. Organizations running ZCS mail servers should treat this as an imminent compromise risk.

Updated Aug 22, 2026

rcen8ngogsworkflow-automationai-assisted-exploitationsigned-driver-abuseliving-off-the-landagent-relevantself-hosted-tools

This roundup covers multiple distinct security issues, including a remote code execution flaw in the Gogs self-hosted Git service, a workflow-to-RCE chain in the n8n automation platform, abuse of signed drivers for defense evasion, and use of AI models (GLM-5.3) to assist in exploit research. Collectively these lower the barrier for attackers by chaining trusted functionality and legitimate software behaviors into compromise paths.

Updated Aug 21, 2026

phishingoauth-abusecredential-theftsocial-engineeringrussiastate-sponsoredaccount-takeoverwhatsappgoogle-oauth

Three suspected Russian cyber espionage clusters (UNC6293, UNC7005, UNC5976) are abusing legitimate Google OAuth flows and WhatsApp device-linking features to hijack accounts of individuals in academia, aerospace/defense, government, and think tanks across Europe and the U.S. These campaigns rely on persistent, adaptive social engineering rather than exploiting software vulnerabilities, making them difficult to detect with traditional malware defenses.

Updated Aug 21, 2026