Conventional Threats Watchlist

Browse by attack type

Showing 341–360 of 804 threats, newest first

routercommand-injectiontelnetfirmwarerceiotnetwork-device

A critical command injection vulnerability exists in the TelnetSSH configuration function of MSI Radix AXE6600 router firmware v781521, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This flaw could be leveraged to fully compromise home and small-office network infrastructure, enabling traffic interception, lateral movement, or botnet recruitment.

Updated Aug 11, 2026 · CVSS 9.8

routercommand-injectionrcesshfirmwarenetwork-deviceunauthenticated

A critical command injection vulnerability exists in the TelnetSSH configuration function of MSI Radix AXE6600 routers running firmware v781521, allowing remote attackers to execute arbitrary commands with root privileges. Given the CVSS score of 9.8, this flaw is likely remotely exploitable without authentication, making affected devices prime targets for botnet recruitment, traffic interception, or use as network pivot points.

Updated Aug 11, 2026 · CVSS 9.8

CISA-KEVcommand-injectionload-balancernetwork-applianceactive-exploitationedge-device

A critical command injection vulnerability in Progress Kemp LoadMaster, tracked as CVE-2026-8037 (CVSS 9.6), has been added to CISA's Known Exploited Vulnerabilities catalog after 792 reported exploitation attempts in the wild. The flaw allows attackers to achieve arbitrary command execution on affected load balancer appliances, posing severe risk to organizations relying on this infrastructure for traffic management.

Updated Aug 10, 2026 · CVSS 9.6

RMMexploitation-in-the-wildMSPsupply-chain-riskremote-monitoringhotfixagent-relevant

N-able has released a second hotfix for its N-central Remote Monitoring and Management (RMM) platform after observing threat actors actively exploiting a recently disclosed vulnerability and evolving their attack techniques to persist on managed endpoints. The vendor is expanding protections beyond the initial patch, indicating attackers reaching into managed customer environments through the compromised RMM infrastructure.

Updated Aug 10, 2026

prompt-injectionagent-relevantAI-securitydata-exfiltrationAtlassianindirect-prompt-injectionRAGLLM-tool-use

Security researchers demonstrated that Atlassian's Rovo AI assistant can be manipulated via attacker-controlled content (e.g., uploaded files or embedded instructions) to collect Jira and Confluence data accessible to a signed-in user and exfiltrate it to an external server. Two independent research teams found separate exploitation paths; only one has been confirmed remediated by Atlassian.

Updated Aug 10, 2026

sharepointgovernmentdata-breachaccount-compromiseon-premises

Switzerland's Federal Office of Information Technology disclosed that attackers exploited vulnerabilities in on-premises Microsoft SharePoint servers to compromise roughly 200 government accounts. The incident highlights ongoing risks tied to unpatched or exposed SharePoint deployments within critical government infrastructure.

Updated Aug 10, 2026

routercommand-injectionrcefirmwareiotunauthenticatednetwork-infrastructure

A critical command injection vulnerability exists in the alg function of MSI Radix AXE6600 router firmware v781521, allowing remote attackers to execute arbitrary commands with root privileges. With a CVSS score of 9.8, this flaw could enable full device takeover, network pivoting, and traffic interception on affected routers.

Updated Aug 10, 2026 · CVSS 9.8

routercommand-injectionrceiotfirmwareunauthenticated-rce

A critical unauthenticated command injection vulnerability (CVE-2026-71986) exists in the dmz function of MSI Radix AXE6600 router firmware v781521, allowing remote attackers to execute arbitrary commands and gain root access. With a CVSS score of 9.8, this flaw poses severe risk to any network relying on the affected device for perimeter security or connectivity.

Updated Aug 10, 2026 · CVSS 9.8

routercommand-injectionrceiotnetwork-infrastructureunauthenticated

A critical command injection vulnerability exists in the accesscontrol function of MSI Radix AXE6600 router firmware v781521, allowing remote attackers to execute arbitrary commands with root privileges. Given the CVSS score of 9.8, exploitation likely requires no authentication and results in full device compromise, enabling attackers to intercept, redirect, or manipulate all network traffic passing through the device.

Updated Aug 10, 2026 · CVSS 9.8

router-vulnerabilitycommand-injectionrceiotnetwork-infrastructureunauthenticated-exploit

A critical unauthenticated command injection vulnerability exists in the urlfilter function of MSI Radix AXE6600 router firmware v781521, allowing remote attackers to execute arbitrary commands with root privileges. Given the CVSS score of 9.8 and remote exploitability without authentication, this vulnerability poses severe risk to any network using affected devices, potentially enabling full network compromise, traffic interception, or pivot points for further attacks.

Updated Aug 10, 2026 · CVSS 9.8

routercommand-injectionrcefirmwareiotnetwork-deviceunauthenticated

A critical unauthenticated command injection vulnerability exists in the wps.cgi interface of MSI Radix AXE6600 routers running firmware v781521. Remote attackers can inject malicious commands via the pin2g, pin5g, or pin6g parameters to achieve arbitrary command execution with root privileges. This flaw can allow full device takeover, enabling network-level man-in-the-middle attacks, traffic interception, and pivoting into internal networks.

Updated Aug 10, 2026 · CVSS 9.8

metabasesql-injectionzero-dayunauthenticated-rcebusiness-intelligenceagent-relevantrag-pipelinecredential-exposure

Metabase has disclosed a maximum-severity (CVSS 10.0) zero-day vulnerability being actively exploited in the wild, allowing unauthenticated remote attackers to inject arbitrary SQL and gain administrative access to Metabase instances. No CVE identifier has been assigned yet, but exploitation has already been observed, making this an urgent patching priority for any organization running Metabase for business intelligence or analytics.

Updated Aug 9, 2026 · CVSS 10

webmailcss-injectionphishingcredential-theftui-redressagent-relevantemail-security

PortSwigger researcher Gareth disclosed a class of CSS-based attacks that allow content embedded in an email to escape its intended message boundary and manipulate the surrounding webmail interface. Affecting Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, the techniques can capture passwords, hijack trusted UI elements, leak session tokens, take over third-party accounts, and manipulate AI tools that process email content.

Updated Aug 9, 2026

critical-infrastructureportstransportationoperational-disruptionIT-OT

The North Carolina Ports Authority confirmed a cyberattack that disrupted IT systems and slowed operations at the Port of Wilmington, Port of Morehead City, and Charlotte Inland Port. Details on the attack vector, threat actor, and data impact have not been publicly disclosed as of this report. The incident highlights ongoing risk to critical maritime and logistics infrastructure.

Updated Aug 9, 2026

banking-malwareBECclipboard-hijackingcryptocurrency-theftbrowser-manipulationemail-compromisefinancial-fraud

Gen's H1 2026 Threat Report details two distinct financially-motivated attack chains: one leveraging compromised legitimate business email accounts combined with browser manipulation to deliver banking malware, and another using clipboard hijacking malware to silently redirect cryptocurrency payments to attacker-controlled wallets. Both campaigns rely on abusing trust in legitimate channels (real inboxes, clipboard contents) rather than novel exploits, making detection via traditional signature-based tools more difficult.

Updated Aug 9, 2026

supply-chainbackdoorvideo-conferencinghacktivismtrojanized-installerrussiaagent-relevant

The Head Mare hacktivist group has compromised unpatched TrueConf video conferencing servers to replace legitimate client installers with trojanized versions containing backdoors. This supply-chain attack allows attackers to distribute malware to any organization or user downloading updates from compromised TrueConf servers, posing significant risk to enterprise communication infrastructure.

Updated Aug 9, 2026

d-linkrouterbuffer-overflowrceiotunauthenticatednetwork-perimeter

A critical unauthenticated buffer overflow vulnerability affects D-Link DWR-M961 routers running hardware version C1 with a specific firmware build. Remote attackers can send crafted overly long strings to the test4, ssid2, and username fields of the quicksetup.cgi interface to achieve arbitrary command execution or crash the device. With a CVSS score of 9.8, this flaw poses a severe risk to any exposed device, enabling full device takeover, network pivoting, or denial of service.

Updated Aug 9, 2026 · CVSS 9.8

D-Linkrouterbuffer-overflowRCEIoTnetwork-applianceCVE-2026-71957

A critical buffer overflow vulnerability exists in D-Link DWR-M961 routers (hardware version C1, firmware 1.1.2_C1_202602110044) in the app.cgi web management interface. A remote, unauthenticated attacker can trigger the flaw by submitting an overly long string to the netAcc.addlist[].name field, enabling arbitrary command execution or causing a denial of service. Given the CVSS score of 9.8, this vulnerability poses a severe risk to any network relying on the affected device for connectivity or perimeter security.

Updated Aug 9, 2026 · CVSS 9.8

d-linkcommand-injectionrouteriotrceunauthenticatednetwork-infrastructure

A critical unauthenticated command injection vulnerability affects D-Link DWR-M961 routers (hardware version C1, firmware 1.1.2_C1_202602110044). Remote attackers can execute arbitrary commands with root privileges via the netDig.ping.dst parameter in the app.cgi interface, enabling full device takeover. With a CVSS score of 9.8, this vulnerability poses severe risk to any network relying on affected devices for connectivity.

Updated Aug 9, 2026 · CVSS 9.8

iotroutercommand-injectionrced-linkunauthenticatednetwork-device

A critical unauthenticated command injection vulnerability affects D-Link DWR-M961 routers running firmware prior to 1.1.5_C1_202607071108. Attackers can exploit the fota_url parameter in the LTE FOTA upgrade interface to execute arbitrary commands with root privileges, potentially leading to full device compromise. Given the CVSS score of 9.8 and remote exploitability, this poses a severe risk to any network relying on this device for connectivity.

Updated Aug 9, 2026 · CVSS 9.8