Conventional Threats Watchlist

Browse by attack type

Showing 641–660 of 804 threats, newest first

kev-catalogknown-exploited-vulnerabilityoracle-ebsknx-protocolprivilege-escalationactive-exploitationfederal-agenciespatch-management

CISA added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: a KNX Protocol account lockout flaw (CVE-2023-4346) and an Oracle E-Business Suite improper privilege management vulnerability (CVE-2026-46817). Under BOD 26-04, FCEB agencies must prioritize remediation of these vulnerabilities on publicly exposed assets due to evidence of active in-the-wild exploitation.

Updated Jul 16, 2026

advisorybest-practicesvulnerability-disclosurepolicycisansa

This is not a threat but a joint CISA/NSA and international partner guidance document outlining best practices for establishing a Coordinated Vulnerability Disclosure (CVD) program. It advises software manufacturers and online service providers on creating vulnerability disclosure policies, triage processes, CVE assignment, and use of third-party intermediaries. The goal is to help organizations build collaborative relationships with security researchers and improve overall vulnerability management maturity.

Updated Jul 16, 2026

symfonyphpweb-frameworkbypassincomplete-fixagent-relevantrce-riskconfiguration-manipulation

A flaw in Symfony's fix for CVE-2024-50340 fails to properly prevent attacker-controlled environment flags from reaching the application via a discrepancy between parse_str() and the web SAPI's handling of $_GET. This allows remote attackers to craft query strings that manipulate $_SERVER['argv'] to inject --env or --no-debug flags, potentially flipping an application into debug mode or altering its environment configuration. Given the 9.8 CVSS score, this is a critical, low-complexity, remotely exploitable issue affecting a widely used PHP framework.

Updated Jul 16, 2026 · CVSS 9.8

authentication-bypassjwtoidcsymfonyphpagent-relevantidentity-provider

A flaw in Symfony's OidcTokenHandler::verifyClaims() fails to enforce mandatory audience, issuer, and expiry claims when validating JWTs, allowing a validly signed but incomplete token to bypass verification. This could let an attacker with any validly signed JWT (potentially from an unrelated issuer or expired context) authenticate as a legitimate user against affected Symfony applications. The issue is fixed in Symfony 6.4.40, 7.4.12, and 8.0.12.

Updated Jul 16, 2026 · CVSS 9.1

symfonyphpauthentication-bypassmtlsclient-certificateweb-frameworkagent-relevant

A critical authentication bypass vulnerability affects Symfony's X509Authenticator component, where an unanchored regex used to parse client certificate distinguished names (DN) can be exploited by an attacker holding any trusted certificate. By embedding 'emailAddress=victim' within an unexpected RDN field like CN, an attacker can impersonate any user identified by email in a mutual TLS authentication scheme.

Updated Jul 16, 2026 · CVSS 9.1

sharepointrcedeserializationunauthenticatedagent-relevant

CVE-2026-58644 is a critical unauthenticated remote code execution vulnerability in Microsoft Office SharePoint caused by unsafe deserialization of untrusted data. An attacker can exploit this over the network without authentication to achieve full code execution on the SharePoint server, posing severe risk to any organization hosting on-premises SharePoint. Given the CVSS score of 9.8, this vulnerability is likely to be rapidly weaponized following disclosure.

Updated Jul 16, 2026 · CVSS 9.8

fortinetforticlientemscertificate-validationinformation-disclosuremitmcve-2026-59836

CVE-2026-59836 is an improper certificate validation flaw in Fortinet FortiClientEMS affecting versions 7.2, 7.4.0-7.4.1, and 7.4.3-7.4.5, which could allow an attacker to gain access to sensitive information. The vulnerability likely enables man-in-the-middle style attacks due to insufficient validation of TLS/SSL certificates during communications.

Updated Jul 16, 2026 · CVSS 7.5

icsotbuilding-automationknxaccount-lockoutphysical-securitycisa-kev

CVE-2023-4346 is a vulnerability in the KNX Protocol's Connection Authorization Option 1 mechanism that allows an attacker to exploit an overly restrictive account lockout to purge all devices lacking additional security options and lock devices via a BCU key. This affects building automation and industrial control deployments using KNX, potentially causing denial of service and loss of device control. CISA has added this CVE to its Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild.

Updated Jul 16, 2026

agent-relevantbrowser-extensionai-agentclaude-for-chromeanthropicprivilege-escalationdata-exposurerogue-extension

Security researchers found that Claude for Chrome, Anthropic's browser-based AI agent, can be manipulated by any other malicious browser extension capable of injecting a script into claude.ai. This allows a rogue extension to trigger Claude's authenticated agent actions, silently reading a victim's Gmail, Google Docs (including comments), and Calendar without direct user consent for that specific action. The flaw is related to but distinct from the previously disclosed 'ClaudeBleed' issue, sharing the same rogue-extension prerequisite but differing in the scope of accessible data.

Updated Jul 15, 2026

SAPNetWeaverABAPmemory-corruptionout-of-bounds-writeenterprise-softwarepatch-tuesday

SAP has patched a critical out-of-bounds write vulnerability (CVE-2026-44747, CVSS 9.9) in NetWeaver Application Server ABAP that allows an authenticated attacker to trigger memory corruption, potentially exposing or modifying sensitive business data. The flaw was addressed as part of SAP's July 2026 security update cycle alongside other vulnerabilities.

Updated Jul 15, 2026 · CVSS 9.9

microsoftpatch-tuesdayzero-dayactive-exploitationwindowsvulnerability-managementagent-relevant

Microsoft's July 2026 Patch Tuesday addressed 622 CVEs, its largest release on record and more than triple the prior high, including two zero-day vulnerabilities confirmed to be under active exploitation. The advisory was informed by incident responders, indicating real-world attack activity preceded the patches. Organizations should prioritize immediate patching given the scale of the release and confirmed in-the-wild abuse.

Updated Jul 15, 2026

githubinfostealermalwaresupply-chaintyposquattingsoftware-impersonationagent-relevant

A threat actor has created nearly 300 fake GitHub repositories impersonating legitimate software and security tools to distribute infostealer malware. Developers and security researchers searching for these tools risk downloading and executing malicious code disguised as trusted projects.

Updated Jul 15, 2026

BECbusiness-email-compromiseinvestment-fraudmoney-launderinglaw-enforcement-actionfinancial-crime

Spanish National Police dismantled a cybercrime and money-laundering network responsible for approximately €140 million ($160 million) in losses through investment fraud and business email compromise (BEC) schemes. Four suspects were arrested in connection with the operation, which targeted victims through social engineering and fraudulent financial transactions.

Updated Jul 15, 2026

SonicWallSMA1000zero-dayVPNremote-accessedge-deviceexploited-in-the-wild

SonicWall has disclosed that two vulnerabilities in its SMA1000 Secure Mobile Access appliances are being actively exploited as zero-days. The company has released security updates and is urging all customers to patch immediately to prevent further compromise.

Updated Jul 15, 2026

ICSSCADADLL-hijackinglocal-privilege-escalationABBCWE-427critical-infrastructure

ABB disclosed CVE-2025-13162, an uncontrolled search path (DLL hijacking) vulnerability affecting Online Builder (ONB) as included in Control Builder A and 800xA for Advant Master. A local attacker with prior system access could place a malicious DLL in an unrestricted application directory to achieve arbitrary code execution on the affected node.

Updated Jul 15, 2026 · CVSS 4.4

ICSOTprivilege-escalationlinux-kernelABBcritical-infrastructureCWE-669

A high-severity local privilege escalation vulnerability (CVE-2026-31431, 'Copy Fail') affects ABB Ability Edgenius edge computing platforms due to a flaw in the Linux kernel's algif_aead cryptographic interface. A locally authenticated user or compromised container workload could exploit incorrect in-place memory operations to gain full root access on affected devices. ABB has released version 3.2.4.1 to remediate the issue.

Updated Jul 15, 2026 · CVSS 7.8

CISAKEVSonicWallSSRFcode-injectionMicrosoftActive-DirectorySharePointfederalBOD-26-04agent-relevant

CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities Catalog, affecting SonicWall SMA1000 appliances (SSRF and code injection) and Microsoft Active Directory Federation Services and SharePoint Server (access control and authentication bypass issues). These flaws are being actively exploited in the wild and pose significant risk to federal and enterprise networks, with BOD 26-04 mandating rapid remediation for FCEB agencies.

Updated Jul 15, 2026

apache-kylinos-command-injectionrcecve-2026-62392unauthenticated-possibleagent-relevant

Apache Kylin versions 4 through 5.0.3 contain a critical OS command injection vulnerability where backend API job configuration parameters are passed unsanitized to the OS command line, allowing attackers to execute arbitrary commands on the host. With a CVSS score of 9.8, this flaw poses severe risk to any organization running affected Kylin instances, particularly those exposed to untrusted networks. Users should upgrade immediately to version 5.0.4, which resolves the issue.

Updated Jul 15, 2026 · CVSS 9.8

sql-injectionapache-kylindata-analyticsrag-pipelineagent-relevant

A critical SQL injection vulnerability (CVE-2026-62390) affects Apache Kylin versions 4 through 5.0.3, stemming from improper neutralization of special elements in a backend API that refreshes the table catalog. Successful exploitation could allow attackers to manipulate generated SQL queries, potentially leading to unauthorized data access, modification, or full database compromise. Users should upgrade to version 5.0.4 to remediate the issue.

Updated Jul 15, 2026 · CVSS 9.8

apache-dorisbroken-authenticationrest-apiunauthenticated-accessdenial-of-servicedata-infrastructureagent-relevant

Apache Doris versions prior to 3.1.0 expose Frontend (FE) HTTP REST administrative APIs without proper authentication enforcement, allowing unauthenticated network attackers to perform privileged administrative operations. This can lead to cluster instability, unauthorized configuration changes, or denial of service against the analytics cluster.

Updated Jul 15, 2026 · CVSS 9.1