Conventional Threats Watchlist

Browse by attack type

Showing 321–340 of 804 threats, newest first

chromeandroidnotification-abusebrowser-securityanti-abusegoogle

Google announced that Chrome's anti-abuse systems are now blocking over 7 billion unwanted push notifications per day on Android as of Q1 2026. This is a defensive product improvement rather than an active threat, reflecting Google's ongoing efforts to curb notification spam and deceptive web push abuse.

Updated Aug 12, 2026

medical-deviceIoTBLEauthentication-bypasshard-coded-credentialssession-hijackinghealthcareICS-medical-advisoryprivacy

CISA disclosed eight vulnerabilities in the Mira Hormone Monitor firmware and companion Mira Android App, including missing BLE authentication, hard-coded credentials, and a broken login endpoint that returns valid session tokens for any password. Successful exploitation could allow attackers to hijack user accounts, exfiltrate or forge sensitive reproductive health data, track users physically via BLE, and cause denial-of-service on the device.

Updated Aug 12, 2026 · CVSS 9.8

CISAKEVvulnerability-managementCiscoWindowsMetabaseSQL-injectionuse-after-freeheap-overflowBOD-26-04agent-relevant

CISA added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities Catalog: a heap inspection flaw in Cisco Secure Firewall ASA/FTD, a use-after-free in the Windows Ancillary Function Driver for WinSock, and a SQL injection vulnerability in Metabase. Federal agencies are required under BOD 26-04 to remediate these on a prioritized timeline, and all organizations are strongly encouraged to patch given confirmed in-the-wild exploitation.

Updated Aug 12, 2026

medical-deviceiotbluetooth-low-energyhidden-functionalityhardware-vulnerabilityhealthcareunauthenticated-access

The Pulsetto Vagus Nerve Stimulator firmware accepts undisclosed, unauthenticated Bluetooth Low Energy commands that are not issued by the official companion app but are still processed by the device. Successful exploitation could allow a nearby attacker to disable electrical safety mechanisms or alter stimulation output settings, posing a physical safety risk to users. The vendor has not responded to CISA's coordination attempts, and no patch is currently available.

Updated Aug 12, 2026 · CVSS 8.1

adobecampaign-classicrceauthorization-bypassunauthenticatedmarketing-platform

A critical Incorrect Authorization vulnerability in Adobe Campaign Classic (ACC) allows attackers to achieve arbitrary code execution in the context of the current user without any user interaction. With a CVSS score of 10.0 and a changed scope, successful exploitation could lead to full compromise of the marketing automation platform and downstream systems it integrates with.

Updated Aug 12, 2026 · CVSS 10

authentication-bypassjwt-forgeryssohard-coded-secretunauthenticated-rce-pathidentity-provideragent-relevant

MaxKey SSO contains a hard-coded JWT signing secret that allows unauthenticated attackers to forge valid admin-level JWT tokens and bypass authentication entirely via the password-skipped login endpoint. This grants full access to SSO application configuration and downstream application secrets, effectively compromising every service federated through the affected MaxKey instance.

Updated Aug 12, 2026 · CVSS 9.8

ICSOTindustrial-control-systemsunauthenticated-RCEnode-redsiemensedge-deviceagent-relevant

A critical vulnerability (CVSS 10.0) in Siemens SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED allows unauthenticated remote attackers to execute arbitrary code with maximum privileges via the exposed Node-RED HTTP interface. Attackers can craft malicious flows to invoke system command nodes, achieving full device compromise with no authentication required.

Updated Aug 12, 2026 · CVSS 10

sql-injectionunauthenticated-rceweb-applicationdatabase-compromisetravel-industry

CVE-2026-19425 is a critical unauthenticated SQL injection vulnerability in Win Men International's Travel Agency Management System, allowing remote attackers to fully compromise backend databases without credentials. With a CVSS score of 9.8, exploitation could lead to complete data exfiltration, modification, or destruction, posing severe risk to organizations relying on this platform for customer and booking data.

Updated Aug 12, 2026 · CVSS 9.8

sql-injectionmetabaseunauthenticated-rcedata-exfiltrationcisa-kevagent-relevant

Metabase, a widely used open-source business intelligence and analytics platform, contains an unauthenticated SQL injection vulnerability that can grant attackers full administrative access to the application. CISA has added this CVE to its Known Exploited Vulnerabilities catalog with a short remediation window, indicating active exploitation in the wild. Successful exploitation exposes connected database credentials and any data accessible through those connections.

Updated Aug 12, 2026

windowsprivilege-escalationuse-after-freekernel-driverCISA-KEVagent-relevant

CVE-2026-68820 is a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys) that allows a locally authenticated attacker to escalate privileges to SYSTEM. It has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild, with federal agencies required to remediate by August 25, 2026.

Updated Aug 12, 2026

ciscoasaftdfirewalldoscisa-kevnetwork-infrastructureunauthenticated-rce-risk

A heap inspection vulnerability in Cisco Secure Firewall ASA and FTD allows an unauthenticated, remote attacker to trigger an unexpected device reload, causing a denial-of-service condition. CISA has added this CVE to its Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild, with a mandated remediation due date of August 14, 2026.

Updated Aug 12, 2026

weekly-recapsupply-chainzero-dayMCPagent-relevantrouter-backdoorAI-security

This week's roundup highlights a Metabase zero-day, supply-chain attacks targeting Model Context Protocol (MCP) tooling used in AI agent ecosystems, and backdoors found in consumer/enterprise routers. The report is an aggregated digest rather than a single incident, but the MCP supply-chain angle is directly relevant to organizations deploying AI agents and LLM tool-use frameworks.

Updated Aug 11, 2026

ransomwarechina-linkedstorm-1175n-centralrmm-exploitationdouble-extortion

Microsoft has identified Storm-1175, a financially motivated China-linked threat actor, deploying a new ransomware strain called StormEncryptor, marking a shift from their prior use of Medusa ransomware. Initial access is suspected to involve exploitation of a flaw in N-central, a remote monitoring and management (RMM) platform commonly used by MSPs to administer client endpoints and infrastructure.

Updated Aug 11, 2026

vendor-contentnot-a-threatapplication-securitydevsecopsAI-generated-codeinformational

This item is promotional content advertising a webinar about managing security risks introduced by AI-accelerated software development, rather than an active threat, vulnerability, or campaign. It highlights a legitimate industry concern: as AI coding assistants increase code output volume, security teams may struggle to keep pace with vulnerability review, dependency management, and risk prioritization.

Updated Aug 11, 2026

product-launchai-security-toolingvulnerability-researchpentestingnot-a-threatagent-relevant

This is a product announcement rather than an active threat: OpenAI has released 'GPT-5.6 Cyber,' a specialized model for vulnerability research, penetration testing, incident response, and remediation, gated to approved users. The release has security implications for both defenders and potential misuse by threat actors if access controls are bypassed or credentials are compromised.

Updated Aug 11, 2026

wordpresssupply-chainplugin-compromiseadmin-takeoverweb-security

A threat actor compromised the upstream infrastructure of BdThemes, a premium WordPress plugin developer, and tampered with a remote JSON feed served to site administrators. This modified feed was used to silently create rogue administrator accounts on affected WordPress installations, granting attackers persistent backend access.

Updated Aug 11, 2026

OTICScritical-infrastructureenergyAPNcellular-networkremote-accessindustrial-control-systems

Hackers breached the operational technology (OT) network of a small Polish heat-and-power plant serving approximately 50,000 residents by exploiting a private Access Point Name (APN) used for remote cellular connectivity. The incident, disclosed as having occurred the prior year, highlights how insufficiently secured private cellular networks can serve as an overlooked pathway into critical infrastructure control systems.

Updated Aug 11, 2026

SAPcommand-injectionRCEmanufacturinginput-validationcritical-infrastructure

A critical command injection vulnerability affects SAP Manufacturing Integration and Intelligence (MII), allowing a high-privileged attacker to submit crafted input that is insufficiently validated, leading to arbitrary OS command execution. Exploitation could fully compromise confidentiality, integrity, and availability of the affected system. Organizations running SAP MII in manufacturing or industrial environments should prioritize patching.

Updated Aug 11, 2026 · CVSS 9.1

sapnetweavermemory-corruptionunauthenticated-rcedoserpcritical-infrastructure

A critical unauthenticated vulnerability (CVE-2026-34265) affects SAP NetWeaver Application Server ABAP, stemming from logical errors in DIAG protocol parsing that lead to memory corruption. With a CVSS score of 9.8, attackers can remotely disclose sensitive information or crash affected systems without any authentication, posing severe risk to organizations running SAP ERP environments.

Updated Aug 11, 2026 · CVSS 9.8

kubernetesauthentication-bypassprivilege-escalationmaasmulti-tenancyagent-relevantai-infrastructureapi-security

CVE-2026-14450 is a critical authentication bypass vulnerability in the Model-as-a-Service (MaaS) API layer fronted by Kuadrant's AuthPolicy gateway. Any pod within the affected Kubernetes cluster can forge the X-MaaS-Username and X-MaaS-Group HTTP headers, which are trusted verbatim without first-party verification, enabling full cross-tenant privilege escalation. This allows attackers to mint ServiceAccount tokens in other tenants' namespaces, revoke arbitrary API keys, and exfiltrate model access configuration data.

Updated Aug 11, 2026 · CVSS 9.9