Conventional Threats Watchlist

Browse by attack type

Showing 221–240 of 804 threats, newest first

CISAKEVSSRFMLflowMLOpsagent-relevantvulnerability-managementBOD-26-04

CISA has added CVE-2026-64849, a Server-Side Request Forgery (SSRF) vulnerability in MLflow, to its Known Exploited Vulnerabilities Catalog based on confirmed active exploitation. Federal agencies are required under BOD 26-04 to remediate this vulnerability on a prioritized basis, and CISA urges all organizations to do the same given active in-the-wild attacks.

Updated Aug 20, 2026

oraclefusion-middlewareunauthenticated-rceweb-servicescve-2026-60737agent-relevant

A critical, easily exploitable vulnerability exists in Oracle Web Services Manager (Web Services Security component) affecting versions 12.2.1.4.0 and 14.1.2.0.0. An unauthenticated attacker with network access via HTTP can compromise the product, gaining unauthorized creation, deletion, modification, and full read access to all data accessible to Oracle Web Services Manager.

Updated Aug 20, 2026 · CVSS 9.1

oracleidentity-managementunauthenticated-rcefusion-middlewareiamcritical-infrastructureagent-relevant

A critical unauthenticated remote vulnerability affects Oracle Identity Manager's Legacy UI component within Oracle Fusion Middleware, allowing full compromise via simple HTTP requests. With a CVSS score of 9.8, this flaw requires no authentication or user interaction, making it highly attractive for mass exploitation once technical details or proof-of-concept code emerge. Organizations running affected versions face risk of complete identity infrastructure takeover, including provisioning, credential, and access control data.

Updated Aug 20, 2026 · CVSS 9.8

oracleidentity-managementprivilege-escalationfusion-middlewareiamagent-relevant

A critical vulnerability (CVE-2026-60720, CVSS 9.9) affects the OIM Legacy UI component of Oracle Identity Manager within Oracle Fusion Middleware, allowing a low-privileged attacker with network HTTP access to fully compromise the system. Due to a scope change, successful exploitation can impact other connected products beyond Oracle Identity Manager itself, making this a high-priority patching target for any organization running affected versions.

Updated Aug 20, 2026 · CVSS 9.9

oracleweblogicrceunauthenticatedt3iiopmiddlewareagent-relevant

A critical, easily exploitable vulnerability in Oracle WebLogic Server allows unauthenticated attackers with network access via the T3 or IIOP protocols to fully compromise the server. With a CVSS score of 9.8 and no required user interaction or privileges, this flaw is highly likely to be weaponized rapidly, as historical WebLogic T3/IIOP vulnerabilities have been favored targets for mass exploitation and ransomware precursor activity.

Updated Aug 20, 2026 · CVSS 9.8

oracleposhospitalityunauthenticated-rcecve-2026-60591network-exploitabledos

CVE-2026-60591 is a critical, easily exploitable vulnerability in Oracle Hospitality Simphony POS software that allows unauthenticated attackers with network access to compromise data integrity and availability. Affected versions span 19.8 through 19.10.1, and successful exploitation can result in unauthorized data modification/deletion and denial of service. Organizations using Simphony in restaurant, hotel, or retail point-of-sale environments should prioritize patching due to the low complexity and lack of authentication required for exploitation.

Updated Aug 20, 2026 · CVSS 9.1

extortionsocial-engineeringransomware-affiliatesecondary-extortionfraud

A threat actor group calling itself 'Ransom Busters' is contacting organizations previously victimized by ransomware attacks, falsely claiming to have hacked the original ransomware operators' infrastructure and offering to delete stolen data for a fee of $20,000 to $60,000. This appears to be a secondary extortion scam preying on already-compromised victims rather than a legitimate data recovery or threat actor takedown service.

Updated Aug 19, 2026

MLflowSSRFcloud-credential-theftMLOpsagent-relevantFUXASCADAactive-exploitation

Threat actors are actively scanning for and exploiting a critical Server-Side Request Forgery (SSRF) vulnerability in MLflow, an open-source AI/ML lifecycle platform, to steal cloud credentials and secrets from exposed metadata services. A separate but related campaign is targeting FUXA, an open-source SCADA/HMI platform used in industrial automation. Both flaws are being weaponized in the wild according to watchTowr and VulnCheck.

Updated Aug 19, 2026

microsoft-copilotLLM-vulnerabilityone-click-exploitdata-exfiltrationprompt-injectionagent-relevantai-security

Varonis Threat Labs disclosed three vulnerabilities, collectively named CoSnitch, in Microsoft Copilot Personal that could allow an attacker to exfiltrate data from a victim's connected apps and Copilot session with a single click on a crafted link. The flaws exploit an undocumented URL parameter surfaced by the assistant itself, enabling silent data leakage without further user interaction.

Updated Aug 19, 2026

security-controlsdetection-gapvendor-reportbehavioral-testingbreach-attack-simulationdefense-validation

This is a vendor research report (Picus Security's Blue Report 2026) rather than an active threat, highlighting that security controls often block well-known attack signatures but fail to detect variant or behavioral approaches achieving the same malicious objective. The report underscores the need for continuous behavioral and adversarial testing rather than relying solely on signature- or IOC-based defenses.

Updated Aug 19, 2026

clopweb-shelldata-theftplmwindchillflexplmextortion

The Clop ransomware gang has deployed a custom Java-based web shell specifically engineered to target PTC Windchill and FlexPLM product lifecycle management servers. The tool is purpose-built to decrypt stored credentials, enumerate file repositories, and exfiltrate sensitive design and engineering data for extortion purposes. This represents an evolution in Clop's tactics toward targeted, application-specific tooling rather than generic ransomware payloads.

Updated Aug 19, 2026

product-announcementiotprivacyconsumer-technot-a-threat

This is a product feature announcement, not a security threat. Comcast is rolling out WiFi-based motion sensing (using channel state information from existing routers/wireless devices) as part of its Xfinity Shield home security platform, enabling presence/motion detection without dedicated cameras or sensors.

Updated Aug 19, 2026

known-exploited-vulnerabilitiesCISAKEVvulnerability-managementfederalpatch-nowagent-relevant

CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog based on confirmed active exploitation: a Microsoft IKE double-free flaw, a SharePoint authentication bypass, a VMware vCenter path traversal bug, and a macOS improper authentication issue. Under BOD 26-04, FCEB agencies must remediate these on an expedited timeline, and CISA urges all organizations to prioritize patching given evidence of in-the-wild exploitation.

Updated Aug 19, 2026

CISAMalcolmnetwork-traffic-analysisRCEpath-traversalauthorization-bypassdenial-of-servicefile-uploadRBAC-bypasszip-bombagent-relevant

Multiple vulnerabilities have been disclosed in CISA's Malcolm network traffic analysis tool suite, including an unauthenticated-adjacent arbitrary PHP code execution flaw (CVE-2026-55676, CVSS 8.8), two nginx/Lua RBAC bypasses via URI normalization mismatches (CVE-2026-63177, CVE-2026-19670), a path traversal in archive extraction (CVE-2026-63134), and two resource-exhaustion/DoS flaws involving malicious archives and decompression bombs (CVE-2026-63133, CVE-2026-19671). Versions prior to 26.06.1/26.07.0/26.08.0 depending on the specific CVE are affected, with vendor patches available and no known public exploitation reported at this time.

Updated Aug 19, 2026 · CVSS 8.8

ICSindustrial-control-systemssiemensbuffer-overflowlocal-code-executionengineering-softwareCWE-121

Siemens Simcenter Femap and Simcenter Nastran versions prior to V2606 contain a stack-based buffer overflow vulnerability triggered when an application binary parses a malicious string as a file argument. Successful exploitation could allow an attacker to achieve remote code execution in the context of the current process, though exploitation requires user interaction (tricking a user into running the binary with a crafted argument).

Updated Aug 19, 2026 · CVSS 7.8

iotfirmwarebuffer-overflowremote-code-executioncameraunpatched-deviceexploit-published

A critical remotely exploitable stack-based buffer overflow has been discovered in TRENDnet TV-IP751WIC IP cameras running firmware 11.03.03, affecting multiple configuration-handling functions within the alphapd web server component. A public exploit exists, and given the device's end-of-life status, no vendor patch is expected, leaving all deployed units permanently vulnerable to remote compromise.

Updated Aug 19, 2026 · CVSS 9.9

iotnetwork-appliancebuffer-overflowrcepublic-exploitnginxembedded-device

A critical stack-based buffer overflow vulnerability has been discovered in the nginx binary bundled with TRENDnet TEW-WLC100 wireless LAN controllers, triggered by manipulation of the HTTP Server header. The flaw allows unauthenticated remote attackers to execute arbitrary code on the device, and a public exploit is already available, making active exploitation highly likely.

Updated Aug 19, 2026 · CVSS 10

privilege-escalationcmsbroken-access-controlgravweb-applicationagent-relevant

Grav CMS before version 2.0.14 contains a broken access control flaw in the admin plugin's group blueprint, allowing a low-privileged delegated admin.users operator to modify the access field and grant themselves super-admin rights. This enables full administrative takeover of the Grav instance, including scheduler and Twig template evaluation capabilities that can be leveraged for remote code execution.

Updated Aug 19, 2026 · CVSS 9.1

xssstored-xssosint-toolingcredential-theftapi-key-exposureweb-application-securityagent-relevant

SpiderFoot fails to sanitize correlation titles derived from untrusted external scan data such as server banners and metadata, allowing attackers to inject malicious HTML/JavaScript. When an operator views the correlations dashboard, the injected script executes in their browser session, potentially exfiltrating stored API keys and session tokens.

Updated Aug 19, 2026 · CVSS 9.3

kubernetesopenshiftacmprivilege-escalationcommand-injectionsql-injectionrcepostgresagent-relevant

A critical injection vulnerability in Red Hat Advanced Cluster Management's acm-search-v2-rhel9 component allows authenticated users, including hub administrators or Search Custom Resource editors, to execute arbitrary shell commands and SQL statements. The flaw stems from improper validation of the WORK_MEM string in the Search CR before it is embedded in a bash script and SQL query, enabling code execution within the privileged postgres pod.

Updated Aug 19, 2026 · CVSS 9.1