Conventional Threats Watchlist

Browse by attack type

Showing 121–140 of 804 threats, newest first

ownCloudauthentication-bypasswebdavCISA-KEVfile-storageagent-relevant

CVE-2023-49105 is an improper authentication vulnerability in ownCloud that allows attackers to access, modify, or delete arbitrary files without valid credentials when a victim's username is known and no signing-key is configured. The flaw has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild. Organizations using ownCloud for file storage or as a backend for automated data pipelines face high risk of unauthorized data access and manipulation.

Updated Aug 28, 2026 · CVSS 9.8

AitMphishing-as-a-servicesession-hijackingMicrosoft365Docusign-abusecredential-theftagent-relevant

A subscription-based adversary-in-the-middle phishing toolkit called NovaCookies is being used to abuse legitimate Docusign notification emails to lure victims into fraudulent Microsoft 365 login flows. The service acts as a reverse proxy that captures authenticated session cookies, allowing attackers to bypass MFA and hijack active Microsoft 365 sessions for $320/month.

Updated Aug 27, 2026

IranIRGCnation-stateespionagebackdoorSSH-tunnelingNimbus ManticoreAPT

Nimbus Manticore, an Iranian state-sponsored APT group affiliated with the IRGC, has expanded its toolset with a new TWOSTROKE-like backdoor and an SSH tunneling utility, according to Group-IB research. The group is characterized as one of the most active Iranian threat actors in 2026, conducting cyber espionage operations using newly discovered infrastructure and malware.

Updated Aug 27, 2026

chinastate-sponsoredcritical-infrastructurenetwork-reconnaissancerouter-exploitationbotnetfbi-disruptionQTFY

The U.S. DoJ and FBI disrupted infrastructure operated by China-linked threat actor QTFY, tied to Nanjing Xinjiuwei Network Technology Company, which used two custom hacking platforms—QScan and QTRouter—to target U.S. critical infrastructure and sensitive networks. The takedown highlights ongoing state-sponsored efforts to compromise network edge devices for espionage and data theft purposes.

Updated Aug 27, 2026

legal-settlementregulatorychild-safetynon-security-incident

Meta has agreed to a proposed settlement of up to approximately $18 billion with a bipartisan coalition of 52 state attorneys general over allegations that Facebook and Instagram were designed to foster compulsive use among children and teenagers. This is a legal and regulatory matter rather than a cybersecurity incident, involving no technical exploitation, vulnerability, or malicious activity.

Updated Aug 27, 2026

rowhammergpu-securityprivilege-escalationdenial-of-servicehardware-attacknvidiaagent-relevant

Researchers disclosed GPUThor, a new Rowhammer-class attack that defeats NVIDIA's ECC memory protections, allowing attackers with local access to induce bit flips leading to denial-of-service or root-level privilege escalation. This is particularly concerning for shared GPU infrastructure such as cloud AI training clusters and multi-tenant inference environments.

Updated Aug 27, 2026

wordpresscmsrceunauthenticatedplugin-vulnerabilityweb-security

A critical vulnerability chain in the widely used Avada WordPress theme allows unauthenticated attackers to achieve remote code execution on affected servers with no user interaction required. Given Avada's large install base as a premium theme, this represents a significant risk of mass exploitation against websites and hosting infrastructure.

Updated Aug 27, 2026

ICSIoTmissing-authorizationCWE-862payment-systemsunauthenticated-accessinformation-disclosure

PayRange API, used to manage internet-connected vending and payment devices, contains a missing authorization vulnerability that exposes verbose device management data to unauthenticated or authenticated attackers. Exploitation could allow information disclosure, denial of service, or manipulation of device-displayed content across the PayRange network. PayRange has not engaged with CISA to remediate the issue, leaving affected deployments exposed.

Updated Aug 27, 2026 · CVSS 8.8

kevcisavulnerability-managementpatch-prioritylegacy-softwarenetwork-applianceagent-relevant

CISA added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation, spanning Red Hat Libuser/ABRT, Microsoft SQL Server, Ajax.NET Professional, Linux Kernel, and Citrix NetScaler ADC/Gateway. BOD 26-04 mandates FCEB agencies prioritize rapid remediation of these on internet-facing assets, particularly those allowing full post-exploitation control. All organizations, including those hosting AI infrastructure, are encouraged to remediate promptly given confirmed in-the-wild exploitation.

Updated Aug 27, 2026

vulnerability-managementsecure-by-designCISAKEVpatch-managementrisk-prioritizationadvisory

CISA released a review analyzing FY2024-2025 vulnerability and exploitation data, finding that most breaches stem from unpatched, well-known vulnerabilities rather than novel attack techniques. The report highlights recurring software weakness classes and provides a risk-based prioritization framework (per BOD 26-04) to help organizations focus remediation efforts before automated and AI-assisted vulnerability discovery becomes more prevalent.

Updated Aug 27, 2026

totolinkroutercgibuffer-overflowrceiotunauthenticatedpublic-exploit

A critical, publicly disclosed stack-based buffer overflow exists in TOTOLINK N600R routers (firmware 4.3.0cu.7647_B20210106) via the Hostname parameter in the setSystemConfig function of cstecgi.cgi. The flaw is remotely exploitable without authentication and carries a maximum CVSS score of 10.0, allowing attackers to potentially achieve remote code execution on affected devices.

Updated Aug 27, 2026 · CVSS 10

authentication-bypassidentity-spoofingdata-exposurecloud-storagealluxioagent-relevantrag-pipelinedata-lake

A critical authentication bypass exists in Alluxio's S3 REST proxy, where default configurations fail to validate AWS Signature Version 4 signatures. This allows unauthenticated attackers to extract usernames from unsigned Authorization headers and impersonate any user or service account, enabling unauthorized read, write, and delete access to arbitrary stored data.

Updated Aug 27, 2026 · CVSS 9.8

adobecampaign-classicos-command-injectionrceunauthenticatedcritical-vulnerability

A critical OS command injection vulnerability in Adobe Campaign Classic (CVE-2026-76197) allows attackers to achieve arbitrary code execution without requiring user interaction, and carries a maximum CVSS score of 10.0. Organizations running ACC for marketing automation should treat this as an urgent patching priority given the scope change and lack of required authentication or interaction.

Updated Aug 27, 2026 · CVSS 10

adobeos-command-injectionrcecampaign-classicunauthenticatedcritical-vulnerability

A critical OS Command Injection vulnerability in Adobe Campaign Classic (ACC) allows an attacker to achieve arbitrary code execution in the context of the current user without requiring any user interaction. With a maximum CVSS score of 10.0 and a changed scope, successful exploitation could allow attackers to pivot beyond the vulnerable component into connected infrastructure.

Updated Aug 27, 2026 · CVSS 10

citrixnetscalerdenial-of-servicecisa-kevedge-devicenetwork-applianceactive-exploitation

CVE-2026-8452 is an improper memory buffer restriction vulnerability in Citrix NetScaler ADC and NetScaler Gateway that can result in denial of service. CISA has added this CVE to its Known Exploited Vulnerabilities catalog with a short remediation window, indicating active exploitation in the wild. Organizations using NetScaler appliances as gateways or load balancers should prioritize patching due to the aggressive due date.

Updated Aug 27, 2026

linux-kernelprivilege-escalationlocal-exploitcisa-kevwatch_queueagent-relevant

CVE-2022-0995 is an out-of-bounds write vulnerability in the Linux Kernel's watch_queue event notification subsystem that allows a local attacker to escalate privileges or crash the system. It is listed in CISA's Known Exploited Vulnerabilities catalog, indicating confirmed active exploitation in the wild. Organizations running affected Linux kernel versions must remediate promptly per CISA's mandated due date.

Updated Aug 27, 2026 · CVSS 7.8

privilege-escalationsymlink-attacklinuxred-hatCISA-KEVeol-software

CVE-2015-5287 is a local privilege escalation vulnerability in Red Hat's Automatic Bug Reporting Tool (ABRT), exploitable via a symlink attack on a predictably named file. The flaw allows local users with certain permissions to escalate privileges on affected Linux systems. This vulnerability has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation in the wild despite its age.

Updated Aug 27, 2026 · CVSS 6.9

linuxprivilege-escalationrace-conditionred-hatcisa-kevlocal-exploit

CVE-2015-3246 is a race condition vulnerability in Red Hat's libuser library that allows authenticated local users to corrupt /etc/passwd, resulting in denial of service or privilege escalation. The flaw has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild despite its age. Organizations still running affected libuser versions on Linux systems should prioritize patching before the specified due date.

Updated Aug 27, 2026

deserializationremote-code-executiondotnetlegacy-softwareend-of-lifeCISA-KEV

Ajax.NET Professional (AjaxPro) is affected by a deserialization vulnerability (CVE-2021-23758) that allows remote code execution through instantiation of arbitrary .NET classes. The affected product is end-of-life, meaning no vendor patch is available, and CISA has added it to the Known Exploited Vulnerabilities catalog due to active exploitation.

Updated Aug 27, 2026

authenticationpasskeyssecurity-featurewhatsappmetaphishing-resistant

Meta has expanded WhatsApp's account security by enabling support for multiple passkeys per account across iOS and Android, allowing users to sign in using phishing-resistant authentication methods on multiple devices. This is a defensive security enhancement rather than a threat, aimed at reducing account takeover risk for over 1 billion existing passkey users.

Updated Aug 26, 2026