Conventional Threats Watchlist

Browse by attack type

Showing 101–120 of 804 threats, newest first

IBM-iprivilege-escalationunauthenticatedsession-hijackingGUI-vulnerability

A critical unauthenticated privilege escalation vulnerability exists in IBM Administration Runtime Expert (ARE) for i, allowing remote attackers to execute actions under another authenticated user's session. This flaw, rated 9.9 CVSS, poses severe risk to IBM i systems used for enterprise administration and automation, potentially enabling full system compromise without prior credentials.

Updated Aug 29, 2026 · CVSS 9.9

kubernetesargo-rolloutsunauthenticated-accessprivilege-escalationci-cdgitopsagent-relevant

Argo Rollouts dashboard versions through 1.10.0 bind to all network interfaces and expose privileged, mutating rollout operations without any authentication, authorization, or CSRF protection. An attacker with network access to the dashboard port can hijack deployment lifecycle controls across all namespaces the operator's kubeconfig can reach, enabling denial of service, unauthorized rollbacks, or malicious image promotion.

Updated Aug 29, 2026 · CVSS 9.8

redpandaadmin-apiunauthenticated-accessmisconfigurationbroker-compromiseagent-relevantdata-streamingrag-pipeline

Redpanda versions through 26.2.2 bind the Admin API to all network interfaces (0.0.0.0:9644) with authentication disabled by default, allowing any network-reachable attacker to be treated as a superuser. This enables unauthenticated creation and deletion of broker accounts, cluster configuration tampering, and disruption of partition replication, posing a critical risk to any exposed deployment.

Updated Aug 29, 2026 · CVSS 9.8

mcpagent-relevantrceunauthenticated-accessai-agent-infrastructuresupply-chaindefault-configuration

The mcp-http-server package used by UI-TARS-desktop's MCP servers defaulted to binding on all network interfaces ('::') with no mandatory authentication middleware, exposing the @agent-infra/mcp-server-commands and @agent-infra/mcp-server-filesystem tools to unauthenticated network access. Any remote client able to reach the exposed port could invoke the run_command tool to execute arbitrary OS commands, or read/write arbitrary files, as the user running the MCP server. The flaw was fixed by changing the default bind address to 127.0.0.1, but the package version number was not incremented, making patch detection reliant on commit history rather than semantic versioning.

Updated Aug 29, 2026 · CVSS 10

supply-chain-attackopen-sourcenpmmalicious-packagescybercrimeextortionarrestlaw-enforcementagent-relevant

Australian Federal Police arrested two suspects believed to be members of TeamPCP, a cybercrime group linked to what is described as the longest-running spree of software supply chain attacks via malicious open-source packages. The group allegedly compromised thousands of global businesses by distributing trojanized open-source software components. While this report covers the law enforcement action, the underlying threat—malicious open-source packages—remains a systemic risk to any organization consuming public package repositories.

Updated Aug 28, 2026

iot-botnetcritical-infrastructuresharepointrcec2-abusescanningexploit-chainwater-utilities

This is a weekly digest from The Hacker News summarizing over 30 distinct security stories, including a 296,000-device IoT botnet, targeting of 100+ water utility systems, and a SharePoint remote code execution exploit chain. The roundup lacks technical depth on any single incident but signals a broad wave of activity spanning critical infrastructure targeting, malicious tooling with delayed payload activation, and abuse of public infrastructure for command-and-control traffic.

Updated Aug 28, 2026

nextjsrceunauthenticatedpath-traversalimage-parsingvercelweb-frameworkagent-relevant

Vercel patched two critical unauthenticated remote code execution vulnerabilities in the Next.js framework: one triggered via specially crafted AVIF image files, and another via a path traversal flaw affecting Windows-hosted servers. Both flaws could allow attackers to fully compromise affected servers without authentication, posing a significant risk to any organization running unpatched Next.js deployments.

Updated Aug 28, 2026 · CVSS 9.8

data-breachaviationcustomer-datawifiPII

Manchester Airports Group (MAG) disclosed a breach in which attackers accessed and stole customer data, including Wi-Fi sign-up information from Manchester, Stansted, and East Midlands airports. The incident highlights ongoing risks to critical transportation infrastructure operators handling large volumes of traveler personal data.

Updated Aug 28, 2026

papercutprint-managementzero-dayrceenterprise-software

PaperCut has disclosed active zero-day exploitation of a vulnerability affecting all versions of its PaperCut NG and PaperCut MF print management software. Attackers are leveraging the flaw in real-world attacks prior to patch availability or widespread patch adoption, echoing previous high-profile PaperCut exploitation campaigns.

Updated Aug 28, 2026

cisakevknown-exploited-vulnerabilitiesownCloudlinux-kerneljfrog-artifactorypatch-managementagent-relevant

CISA has added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: an ownCloud improper authentication flaw, an unspecified Linux Kernel vulnerability, and a JFrog Artifactory path traversal issue. These vulnerabilities pose significant risk to federal and enterprise systems and are subject to expedited remediation under BOD 26-04. Organizations using these technologies should prioritize patching to prevent exploitation.

Updated Aug 28, 2026

ICSOTCNCdenial-of-serviceCWE-1285Mitsubishi Electriccritical-manufacturingfirmware-vulnerability

A vulnerability (CVE-2025-2399) in multiple Mitsubishi Electric CNC Series products allows a remote attacker to trigger an out-of-bounds read by sending specially crafted packets to TCP port 683, resulting in a denial-of-service condition. The flaw affects a wide range of M800/M80/E80, M800V/M80V, and M700V/M70V/E70 series controllers used in industrial manufacturing environments. Vendor fixes are available for most affected product lines, with mitigations recommended for systems that cannot be immediately patched.

Updated Aug 28, 2026 · CVSS 5.9

ICSot-securitycommand-injectionauthentication-bypassremote-access-devicecisa-advisoryunauthenticated-access

The Xiiaozet LK100W device, versions prior to 2.1.240, contains three critical vulnerabilities including OS command injection, missing authentication for a critical function, and an authentication bypass that together could allow a remote attacker to fully compromise the device. Two of the three flaws are rated CVSS v3.1 9.8 (Critical) and require no authentication or user interaction to exploit remotely. CISA has published an advisory recommending immediate firmware update to v2.1.240.

Updated Aug 28, 2026 · CVSS 9.8

icsotrockwell-automationpassword-hashingbcryptcwe-916cisa-advisorycritical-manufacturingtransportation

Rockwell Automation OTTO Fleet Manager versions up to V2.36.2 use a bcrypt implementation with an insufficient work factor, weakening stored password hashes against offline brute-force attacks. Exploitation requires an attacker to first obtain an unencrypted system backup, after which weakly hashed credentials could be cracked more easily. Rockwell has released version 2.36.3 to remediate the issue, along with guidance to enable encrypted system backups.

Updated Aug 28, 2026 · CVSS 6.8

input-validationansi-escape-injectionkey-verification-bypassterminal-spoofingpgpidentity-verificationsupply-chain-riskagent-relevant

A critical flaw in openssl_encrypt (before 1.4.9) allows attackers to inject unsanitized ANSI escape sequences into the email field of identity documents, enabling forgery of the fingerprint verification line shown to users. This undermines the out-of-band verification mechanism designed to prevent key substitution/MITM attacks, allowing attackers to trick users into trusting an attacker-controlled key.

Updated Aug 28, 2026 · CVSS 9.8

cvekey-substitutioncryptographic-flawidentity-verificationfingerprint-bypasssupply-chainagent-relevant

openssl_encrypt versions prior to 1.4.9 fail to properly re-derive and validate cryptographic fingerprints when loading identities from identity.json, allowing attackers to silently substitute public keys while preserving the claimed fingerprint. This enables man-in-the-middle style attacks where encrypted data is protected with attacker-controlled keys and forged signatures pass verification, undermining the core trust model of the identity store.

Updated Aug 28, 2026 · CVSS 9.8

ILIASPHP-object-injectionunauthenticated-RCEdeserializationLMSShibbolethSSOweb-shellpre-auth

A critical unauthenticated remote code execution vulnerability affects the ILIAS learning management system, stemming from insecure PHP deserialization of session data via the Shibboleth logout endpoint. An attacker can seed a malicious serialized object into any live session via the unauthenticated LTI entry point, then trigger its instantiation and destructor via the logout-notification handler to write attacker-controlled content to an arbitrary path under the web root, achieving code execution as the web server user.

Updated Aug 28, 2026 · CVSS 9.8

grav-cmsapi-key-abuseprivilege-escalationbroken-access-controlcve-2026-80203agent-relevant

The getgrav/grav-plugin-api plugin before version 1.0.18 fails to properly validate API key scope in a critical authorization function, allowing an API key with limited privileges to perform super-admin actions if it belongs to a super-admin account. This flaw enables attackers holding a low-scoped but valid API key to disable 2FA, hijack or delete API keys, and manipulate super-admin accounts, effectively granting full administrative takeover.

Updated Aug 28, 2026 · CVSS 9.8

path-traversalrceunauthenticatedfile-uploaddbgptagent-relevantllm-frameworkai-agent-infrastructure

DB-GPT, an open-source LLM/AI agent development framework, contains an unauthenticated path traversal vulnerability in its skill upload endpoint that allows arbitrary file writes anywhere the server process can write. Combined with a broken authentication dependency that grants admin privileges by default, attackers can plant or overwrite Python modules to achieve full remote code execution with no credentials required.

Updated Aug 28, 2026 · CVSS 9.8

path-traversaljfrogartifactorycve-2026-66384cisa-kevsupply-chainagent-relevant

JFrog Artifactory is affected by a path traversal vulnerability that allows an authenticated user to write files outside the intended Docker cache directory under specific remote-repository configurations. CISA has added this CVE to its Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild, with a remediation deadline of September 10, 2026. Organizations using Artifactory as a package/artifact registry should treat this as a priority patching item.

Updated Aug 28, 2026

linuxkernelprivilege-escalationipv6cisa-kevrceagent-relevant

A privilege escalation vulnerability in the Linux Kernel's IPv6 networking subsystem has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild. The flaw affects multiple Linux distributions including SUSE and Red Hat, with a compressed remediation window of only three days from disclosure to due date, signaling high urgency and severity.

Updated Aug 28, 2026