Conventional Threats Watchlist

Browse by attack type

Showing 21–40 of 789 threats, newest first

known-exploited-vulnerabilitiesCISA-KEVpatch-managementsql-injectioncommand-injectionssrfauthentication-bypassrequest-smugglingagent-relevantLLM-gateway

CISA added seven vulnerabilities to its Known Exploited Vulnerabilities catalog based on confirmed active exploitation, spanning products including Sangoma Switchvox, Starlette, Kestra, BerriAI LiteLLM, JFrog Artifactory, and SonicWall SMA1000 appliances. These flaws include SQL injection, OS command injection, SSRF, authentication bypass, and HTTP request smuggling, posing significant risk to organizations with these products exposed to the internet. Federal agencies must remediate per BOD 26-04, and CISA urges all organizations to prioritize patching.

Updated Sep 3, 2026

guidancecrisis-communicationscritical-infrastructureOT-securityCISAincident-responseadvisory

CISA, the FBI, and international partners released joint guidance on best practices for service providers to communicate clearly and effectively during IT and OT outages, whether caused by cyberattacks, human error, equipment failure, or natural hazards. The guidance stresses clarity, accountability, and transparency to reduce public panic, preserve trust, and support containment and recovery efforts during disruptions. This is a policy/best-practice advisory rather than a description of an active threat, exploit, or vulnerability.

Updated Sep 3, 2026

kubernetesmulti-clusterrceroot-privilege-escalationipsecconfig-injectionagent-relevant

A critical vulnerability in Submariner's cert-auth mode allows a malicious cluster to inject arbitrary ipsec.conf directives via an unsanitized CableName field in a Custom Resource Definition. This enables remote code execution as root on gateway nodes through leftupdown hook abuse, fully compromising the multi-cluster networking layer.

Updated Sep 3, 2026 · CVSS 9.1

sonicwallcommand-injectionrceremote-accessvpn-appliancecisa-kevedge-device

CVE-2026-83549 is an OS command injection vulnerability in SonicWall SMA1000 Appliances that allows an authenticated remote attacker with administrative privileges to execute arbitrary OS commands, leading to full remote code execution. CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog with an unusually short three-day remediation window, indicating active exploitation or imminent risk. Organizations using SMA1000 appliances for secure remote access should prioritize immediate patching.

Updated Sep 3, 2026

SonicWallSSRFCISA-KEVremote-accessVPN-applianceunauthenticated-exploit

CVE-2026-83548 is a server-side request forgery vulnerability in SonicWall SMA1000 Appliances that allows a remote, unauthenticated attacker to reach sensitive internal functionality and perform unauthorized operations. CISA has added this CVE to its Known Exploited Vulnerabilities catalog with a compressed remediation window, indicating active or imminent exploitation in the wild. Organizations using SMA1000 for secure remote access should treat this as an urgent patching priority.

Updated Sep 3, 2026

sql-injectionunauthenticated-rcevoipcisa-kevpostgresqlnetwork-appliance

Sangoma Switchvox, a VoIP PBX platform, contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request. This flaw has been added to CISA's Known Exploited Vulnerabilities catalog with an extremely tight remediation window, indicating active exploitation in the wild. Successful exploitation can lead to database compromise and remote code execution on the underlying host.

Updated Sep 3, 2026 · CVSS 9.8

kestraos-command-injectionunauthenticated-rceworkflow-orchestrationcisa-kevagent-relevant

Kestra OSS, an open-source workflow and orchestration platform, contains an OS command injection vulnerability (CVE-2026-49869) that allows unauthenticated remote attackers to create and execute arbitrary workflows without credentials. This vulnerability has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild, with a remediation due date of September 5, 2026.

Updated Sep 3, 2026

starlettepythonasgirequest-smugglingauthentication-bypassagent-relevantsupply-chaincisa-kev

A HTTP request/response smuggling flaw in the Starlette ASGI framework allows attackers to inject paths into the host portion of a request, causing URL reconstruction that can bypass authentication logic dependent on the reconstructed path. CISA has added this to the KEV catalog, and it may be chained with CVE-2026-42271 to escalate impact. Organizations running Starlette-based web services, including those exposing agent APIs, should prioritize patching before the September 16, 2026 due date.

Updated Sep 3, 2026

data-breachidentity-theftPII-exposuredark-webidentity-verificationKYCthird-party-risk

A newly launched dark web identity theft service is selling digital scans of over 153 million U.S. and Canadian drivers licenses, apparently sourced from a breach or insider leak at a Louisiana-based identity verification company. The FBI's New Orleans field office has opened a formal inquiry into the origin of the leaked images. This represents a massive PII exposure event impacting identity verification supply chains widely used for KYC and onboarding processes.

Updated Sep 2, 2026

supply-chainpackagistcomposerphpiosspywaread-fraudmobilemalicious-packagesoftware-composition

Researchers discovered 13 malicious Composer theme packages on Packagist designed to inject JavaScript into Vietnamese movie and comic streaming sites. The injected code performs mobile ad-fraud and gambling-redirect operations and deploys spyware targeting unpatched iOS devices visiting the compromised sites.

Updated Sep 2, 2026

financial-fraudpayment-systemsbrazilbanking-malwarethreat-actorlatin-america

Breeze Comet is a financially motivated threat actor targeting Brazilian financial services, retail, and e-commerce organizations since 2024, specializing in manipulating payment systems and banking software to execute fraudulent transfers. Google Threat Intelligence Group and Mandiant have tracked hundreds of fraudulent transactions attributed to this group, indicating a mature and persistent operation against Brazil's financial ecosystem.

Updated Sep 2, 2026

artifactoryauthentication-bypasssupply-chainci-cddevopsagent-relevantexploitation-in-the-wild

Threat actors are actively exploiting a critical authentication bypass vulnerability (CVE-2026-82329, CVSS 9.8) in JFrog Artifactory just days after public disclosure, allowing attackers to mint administrative access tokens under default configurations. This provides full administrative control over artifact repositories, enabling malicious package injection, credential theft, and downstream supply-chain compromise.

Updated Sep 2, 2026 · CVSS 9.8

data-breachhealthcarePIIPHI

Aesto LLC, operating as Aesto Health, disclosed a data breach impacting more than 9.5 million individuals. The specific attack vector, threat actor, and full scope of compromised data have not been detailed in the initial disclosure. This incident represents a significant healthcare data exposure event given the scale of affected patients.

Updated Sep 2, 2026

phishingremote-access-toolliving-off-the-landinitial-accessscreenconnectendpoint-management-abuseagent-relevant

Threat actors are abusing the legitimate Faronics Deploy endpoint-management platform, likely delivered via phishing, to gain remote administrative control over victim machines. Once access is obtained, attackers use the platform's legitimate deployment capabilities to install ScreenConnect, a remote support tool commonly repurposed by attackers for persistence and lateral movement.

Updated Sep 2, 2026

icsotscadadenial-of-servicerockwell-automationcritical-manufacturingcisa-advisory

A high-severity denial of service vulnerability affects multiple Rockwell Automation Logix controller families, including ControlLogix, CompactLogix, GuardLogix, and their variants. Exploitation via corrupt crafted data can trigger a major nonrecoverable fault (MNRF), requiring physical recovery actions such as program downloads or stage 2 resets. No public exploitation has been reported to date, and vendor firmware fixes are available.

Updated Sep 2, 2026 · CVSS 7.5

ICSOTindustrial-control-systemsrockwell-automationfactorytalk-historianremote-code-executiondenial-of-serviceCISA-advisorycritical-infrastructure

CISA disclosed two vulnerabilities affecting Rockwell Automation Historian ME (FactoryTalk Historian Machine Edition) Series B 5.202 and Series C 7.101. The more severe flaw (CVE-2025-12768, CVSS 8.0) allows a low-privileged authenticated attacker to achieve remote code execution via an out-of-bounds write, while the second (CVE-2026-12661, CVSS 4.5) enables a network-adjacent authenticated attacker to crash the device through a stack-based buffer overflow. No public exploitation has been reported at this time.

Updated Sep 2, 2026 · CVSS 8

ICSOTdenial-of-serviceindustrial-control-systemsrockwell-automationCIP-protocolCVE-2026-9621CVE-2026-9622CVE-2026-9624CVE-2026-9625

Rockwell Automation RSLinx Classic versions up to 4.50 contain four vulnerabilities (integer overflow/underflow and buffer overflow conditions) exploitable via crafted CIP packets, allowing remote unauthenticated attackers to crash the RSLinx Classic service. Successful exploitation causes a denial-of-service condition requiring service restart, potentially disrupting industrial communications in critical manufacturing environments. No public exploitation has been reported at this time.

Updated Sep 2, 2026 · CVSS 8.6

authentication-bypassproxmoxvirtualizationprivilege-escalationagent-relevanteol-softwareapi-vulnerability

A critical authentication bypass vulnerability in Proxmox Virtual Environment allows unauthenticated attackers to log in as any enabled user, including root@pam, by supplying an arbitrary value in the tfa-challenge parameter during API login. This completely circumvents password verification and two-factor authentication, granting full administrative control over the hypervisor. All affected versions are end of life and will not receive official patches, making immediate upgrade the only viable remediation path.

Updated Sep 2, 2026 · CVSS 9.8

kubernetespolicy-bypassprivilege-escalationcontainer-securityadmission-controlleragent-relevant

A logic flaw in Kyverno's policy exception handling (v1.9.0–v1.12.7) allows attackers to bypass enforce-mode security policies by crafting resource names that match a less restrictive PolicyException. This can be exploited to circumvent critical controls such as hostPath volume restrictions, potentially enabling container breakout or node compromise.

Updated Sep 2, 2026 · CVSS 9

wordpressprivilege-escalationaccount-takeoverauthentication-bypasscmsweb-application

The Nokri Job Board WordPress theme (versions up to 1.6.6) contains a critical authentication bypass vulnerability that allows unauthenticated attackers to take over any user account, including administrators. The flaw stems from improper validation of password reset tokens, enabling attackers to reset passwords using empty token values matched against empty or unset user meta fields.

Updated Sep 2, 2026 · CVSS 9.8