Conventional Threats Watchlist

Browse by attack type

Showing 161–180 of 804 threats, newest first

network-appliancecommand-injectionpre-authrceedge-devicecritical-infrastructure

A critical pre-authentication command injection vulnerability affects multiple DrayTek VigorSwitch models, allowing remote attackers to execute arbitrary commands with root privileges without any credentials. Given the CVSS score of 9.8 and the device's role as network infrastructure, this flaw poses an immediate risk of full network compromise. Organizations using DrayTek switches at network edges should treat this as an urgent patching priority.

Updated Aug 25, 2026 · CVSS 9.8

authentication-bypassprivilege-escalationnetwork-device-managementrconfigunauthenticated-rce-pathagent-relevant

rConfig versions 8.0.0 before 8.2.13 contain a critical authentication bypass flaw allowing unauthenticated attackers to self-register accounts that are automatically granted full Administrator privileges. This grants access to stored network device credentials, user data, and API tokens, effectively giving attackers full control over managed network infrastructure.

Updated Aug 25, 2026 · CVSS 9.8

router-exploitrceunauthenticatedfirmware-vulnerabilityiotnetwork-infrastructurebuffer-overflow

A critical unauthenticated remote code execution vulnerability affects Netis NC63 router firmware through V3.0.0.3327, allowing attackers to gain root access via a crafted HTTP request to the device's web management interface. The vulnerability requires no authentication and no user interaction, making it highly exploitable for mass scanning and botnet recruitment. With a CVSS score of 9.8, this represents a severe risk to any network-edge device running the vulnerable firmware.

Updated Aug 25, 2026 · CVSS 9.8

iotrouterauthentication-bypassunpatchedpublic-exploitnetwork-infrastructure

A critical authentication bypass vulnerability exists in EFM ipTIME T24000M routers (up to firmware 14.20.0) affecting the httpcon_check_session_url function within the Session Validation Handler. The flaw allows remote attackers to bypass authentication without credentials, and a public exploit is already available. The vendor has not responded to disclosure attempts, leaving affected devices unpatched and exposed.

Updated Aug 25, 2026 · CVSS 9.8

oraclehttp-serverweblogicaccess-controlkevcisaexploited-in-the-wildagent-relevant

CVE-2026-21962 is an actively exploited improper access control vulnerability in Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in that allows unauthorized creation, deletion, or modification of critical data, as well as unauthorized full access to server-accessible data. CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog with a short remediation window, indicating active in-the-wild exploitation and high urgency for patching.

Updated Aug 25, 2026

entra-ididentityazure-admicrosoftcvss-10privilege-escalationagent-relevant

Microsoft patched a maximum-severity (CVSS 10.0) vulnerability in Entra ID, its cloud identity and access management platform, that could allow remote code execution or full identity compromise. Microsoft initially flagged the flaw as exploited in the wild but later corrected this to confirm no active exploitation occurred prior to disclosure. The vulnerability's severity stems from Entra ID's central role in authentication for Microsoft 365, Azure, and third-party enterprise applications.

Updated Aug 24, 2026 · CVSS 10

gitlabcode-injectionactive-exploitationunauthenticatedci-cdsource-code-managementagent-relevant

A critical unauthenticated code injection vulnerability in GitLab (CVE-2026-19478, CVSS 9.4) is being actively exploited in the wild within days of public disclosure. The flaw allows attackers to modify or delete publicly accessible GitLab projects and rewrite repository data without authentication, posing severe risk to source code integrity and CI/CD pipeline trust.

Updated Aug 24, 2026 · CVSS 9.4

CISAKEVTrueConfself-hosted-communicationsfederal-mandateactive-exploitationRCE

CISA has added two actively exploited vulnerabilities in TrueConf Server, a self-hosted video conferencing and communications platform, to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch immediately. The flaws are being leveraged in the wild, indicating attackers have working exploits and are actively targeting exposed instances.

Updated Aug 24, 2026

not-a-threatproduct-updatemicrosoft-outlookinformational

This item is a routine Microsoft product announcement describing the rollout of a Classic Outlook visual theme for Outlook on the web and New Outlook for Windows users. It contains no security vulnerability, exploit, malware, or threat actor activity. No action is required from a cybersecurity threat-response perspective.

Updated Aug 24, 2026

androidbanking-trojanmobile-malwarevpn-abuseremote-access-trojantoxicpanda

ToxicPanda, an Android banking trojan, has expanded its capabilities to target 349 applications and now supports 167 remote commands. The malware abuses Android VPN permissions to block access to Google Play, likely to prevent security updates or app removal, while enabling device takeover and financial fraud.

Updated Aug 24, 2026

prototype-pollutionnodejsnpmsupply-chainexceljsagent-relevantRAGjson-parsing

A critical prototype pollution vulnerability exists in exceljs-hardened versions prior to 5.0.0, where the deepMerge helper fails to sanitize dangerous keys (__proto__, constructor, prototype) when merging cell note objects. Attackers can craft malicious spreadsheet or JSON input to pollute Object.prototype, potentially leading to remote code execution, denial of service, or security bypass in downstream application logic.

Updated Aug 24, 2026 · CVSS 9.4

xsssanitizer-bypasshtml-parsingmarkdownsupply-chainnodejs-libraryrag-pipelineagent-relevant

justhtml versions up to 1.11.0 fail to escape angle brackets when converting parsed HTML to Markdown via to_markdown(), allowing untrusted HTML content (including entity-decoded text and content from RCDATA/RAWTEXT elements like <title>, <textarea>, <noscript>) to be emitted as raw, executable HTML in Markdown output. This creates a sanitizer bypass that can lead to stored or reflected cross-site scripting when the resulting Markdown is later rendered as HTML. The vulnerability is fixed in version 1.12.0.

Updated Aug 24, 2026 · CVSS 9.8

xsshtml-sanitizationlibrary-vulnerabilityweb-securityinput-validationagent-relevantrag-pipelinellm-tooling

justhtml versions before 1.16.0 contain multiple sanitization bypass flaws that can allow malicious script/style content to survive HTML sanitization, potentially enabling cross-site scripting. The issues mainly affect advanced usage patterns such as reused/mutated policy objects, programmatic DOM input, and custom SVG/MathML-preserving policies rather than the default sanitize=True parsing path.

Updated Aug 24, 2026 · CVSS 9.8

buffer-overflowrouteriotweb-managementremote-code-executionpublic-exploit

A critical stack-based buffer overflow vulnerability affects the Web Management interface of Comfast CF-N1-S wireless routers version 2.6.0.1, exploitable remotely via the NTP timezone configuration endpoint. The exploit code is publicly available, significantly increasing the likelihood of active exploitation, and successful attacks could allow full device compromise.

Updated Aug 24, 2026 · CVSS 9.9

cisconetwork-managementcrossworksecure-workloadcvss-10patch-tuesdaynetwork-infrastructure

Cisco has released patches addressing nine vulnerabilities across its Crosswork platforms and Secure Workload software, five of which carry the maximum CVSS score of 10.0. These flaws affect Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning regardless of device configuration, posing significant risk to network orchestration infrastructure.

Updated Aug 23, 2026 · CVSS 10

vendor-contentSOCsecurity-operationsAI-in-securitynon-incident

This item is promotional/informational content from The Hacker News discussing how Wazuh, an open-source security platform, integrates AI to improve SOC (Security Operations Center) workflows. It does not describe an active threat, vulnerability, exploit, or attack campaign.

Updated Aug 23, 2026

privacylegal-settlementregulatorychild-privacynon-technical

TikTok has agreed to pay $400 million to settle a 2024 U.S. Department of Justice lawsuit alleging violations of child privacy laws, specifically related to prior consent decree obligations. This is a regulatory and legal enforcement action rather than a cybersecurity incident, involving no exploited vulnerability, malware, or technical compromise.

Updated Aug 23, 2026

privacydigital-identityvendor-contentnon-technicalnot-a-threat

This is an informational/promotional article from Anonyome Labs discussing the benefits of using separate digital personas (distinct emails, phone numbers, payment methods) to reduce data broker correlation and limit exposure from breaches and identity theft. It does not describe an active threat, vulnerability, or attack campaign.

Updated Aug 23, 2026

windowsnamed-pipesipcprivilege-escalationaccess-controlendpoint-securityagent-relevant

This report is an educational/advisory piece from ThreatLocker discussing how weak access controls on Windows named pipes can expose privileged services to untrusted or malicious processes. It highlights best practices such as endpoint verification, command authorization, input validation, and least-privilege scoping to mitigate abuse of interprocess communication channels.

Updated Aug 23, 2026

androidiotbotnetproxy-abusead-fraudsupply-chainautomotivemalware

Attackers compromised a legitimate Android device-update application distributed with car head units, using it to deliver malware that enrolls devices into a proxy botnet and conducts ad fraud. This supply-chain compromise leverages a trusted update mechanism to gain persistent access to a large, distributed fleet of embedded automotive devices.

Updated Aug 23, 2026