Other Conventional Threats

Other conventional threat types

Showing 221–240 of 390 threats, newest first

mikrotikrouterossession-managementapi-vulnerabilitynetwork-infrastructurevpn-exposureCWE-613

A session-management flaw in MikroTik RouterOS's API allows authenticated users whose permissions have been downgraded to retain their prior access levels, since sessions are not properly invalidated after permission changes or inactivity timeouts. The advisory description also notes a more severe potential consequence: low-privilege API access could be leveraged to extract a router's WireGuard private key in plaintext, enabling full VPN impersonation and decryption of associated traffic. No public exploitation has been reported at this time.

Updated Aug 1, 2026 · CVSS 4.9

guidanceopen-sourcesoftware-supply-chainrisk-managementSBOMvulnerability-managementCISAagent-relevant

CISA has released guidance titled 'Open Source Software: Security Principles and Practices' to help agencies and organizations securely use, evaluate, and publish open source software. This is not a threat disclosure but a best-practices document covering OSS lifecycle risk management, a new C4 Framework for trust assessment, SBOM usage, secure development, and handling open source AI systems.

Updated Aug 1, 2026

apachetraffic-serveruse-after-freememory-corruptionreverse-proxycdnagent-relevant

A use-after-free vulnerability has been identified in Apache Traffic Server's intercept plugin functionality, affecting multiple major version branches from 8.0.0 through 10.1.3. The flaw could lead to denial of service or potentially further memory corruption impacts on affected proxy deployments. Patches are available in versions 9.2.15 and 10.1.4.

Updated Aug 1, 2026 · CVSS 5.9

apachetraffic-serveroverflowrce-potentialreverse-proxycdnagent-relevant

A vulnerability in the regex_remap plugin of Apache Traffic Server allows stack and integer overflows through crafted substitution input, potentially leading to crashes or remote code execution. The flaw affects a broad range of ATS versions (8.0.0–8.1.9, 9.0.0–9.2.14, 10.0.0–10.1.3) and is rated high severity with a CVSS score of 8.1.

Updated Aug 1, 2026 · CVSS 8.1

apachetraffic-servermemory-corruptionuse-after-freepath-traversalout-of-bounds-writereverse-proxycdn

A vulnerability in the Cripts framework of Apache Traffic Server allows out-of-bounds writes, path traversal, and use-after-free conditions in versions 10.0.0 through 10.1.3. Successful exploitation could lead to memory corruption, potential remote code execution, or unauthorized file access on affected proxy/caching servers. Users should upgrade to version 10.1.4 to remediate the issue.

Updated Aug 1, 2026 · CVSS 8.1

ad-fraudiot-botnetresidential-proxyclick-fraudgeneric-android-tv-boxesconsumer-iotfraud-as-a-service

A widespread analysis of low-cost generic Android TV streaming boxes reveals they covertly enroll users' home internet connections into residential proxy networks and simulate mobile device behavior to commit large-scale ad fraud on AI-generated websites. This scheme defrauds advertisers and online merchants while exposing consumers' networks to third-party abuse without their knowledge or consent.

Updated Jul 31, 2026

roundupvulnerability-digestdns-hijackingbrowser-securitycredential-theftphishingexploit-chainagent-relevant

This is a weekly aggregated security digest covering multiple unrelated stories, including a large batch of Chrome vulnerabilities, ongoing SonicWall device attacks, DNS hijacking incidents, and emerging AI-assisted hacking techniques. The report lacks specific technical depth on any single threat, functioning instead as a curated summary of the week's security news. Organizations should treat this as an index pointing to underlying incidents that require individual investigation rather than a single actionable threat.

Updated Jul 31, 2026

data-breachregulatory-actiontelecomsouth-koreaprivacy-violation

South Korea's Personal Information Protection Commission fined KT Corporation KRW 53.979 billion ($39 million) for data protection violations related to a customer data breach. The incident highlights regulatory scrutiny of telecom operators' handling of subscriber personal information and inadequate security controls.

Updated Jul 31, 2026

OTICSPLCcritical-infrastructurewater-sectorinternet-exposed-devicesdefault-credentialsCISA-alert

CISA reports a significant increase in threat actors targeting internet-exposed programmable logic controllers (PLCs) in the Water and Wastewater Systems Sector, including devices connected via undocumented cellular modems. Attackers have locked out legitimate operators by changing passwords and altering IP configurations, resulting in boil water notices and forced manual operations at affected utilities.

Updated Jul 31, 2026

ICSSCADAschneider-electricout-of-bounds-writelocal-code-executioncritical-infrastructurevulnerability

A high-severity out-of-bounds write vulnerability (CVE-2026-12927) affects the Schneider Electric IGSS Definition module (Def.exe) used to design SCADA mimic diagrams. Exploitation requires a victim to import a malicious CGF file, which could result in data loss or arbitrary code execution, potentially leading to loss of control over the SCADA system. Schneider Electric has released version 18.0.0.26125 to remediate the issue.

Updated Jul 31, 2026 · CVSS 7.8

ICSOTindustrial-control-systemsMitsubishi-ElectricCC-Link-IE-TSNDoSnetwork-protocolCWE-924critical-manufacturing

A high-severity vulnerability (CVSS 7.1) exists in the Mitsubishi Electric CC-Link IE TSN communication protocol due to improper enforcement of message integrity during transmission. An attacker with access to the same network segment could send specially crafted packets under specific timing conditions to tamper with control communication data, potentially causing a denial-of-service condition across a very broad range of Mitsubishi Electric industrial products including PLCs, servo drives, inverters, robots, and HMIs.

Updated Jul 31, 2026 · CVSS 7.1

ICSOTNASAcFSdenial-of-serviceNULL-pointer-dereferenceincomplete-patchCWE-476

A NULL pointer dereference vulnerability exists in the NASA Core Flight System (cFS) Health & Safety (HS) Application version 7.0.1 and earlier, stemming from an incomplete fix for a prior vulnerability (CVE-2026-15352). An attacker able to trigger the affected command under specific conditions can crash the HS application, causing a denial-of-service condition and processor reset. No public exploitation has been observed to date.

Updated Jul 31, 2026 · CVSS 7.5

rceunauthenticateddefault-credentialsh2-databasedockerexposed-consoleagent-relevant

Juggle through version 1.6.0 ships with an exposed and unprotected H2 database web console reachable at /h2-console, secured only by default credentials. Unauthenticated attackers can log in and abuse the H2 CREATE ALIAS technique to invoke Runtime.exec(), achieving arbitrary OS command execution with root privileges on the stock Docker image.

Updated Jul 31, 2026 · CVSS 9.8

sql-injectioncve-2026-4978traffic-managementunauthenticatedcritical-infrastructure

A critical SQL injection vulnerability affects UMAI Vision Traffic Analysis System versions 30 through 33, allowing attackers to manipulate backend database queries. With a CVSS score of 9.8, this vulnerability likely permits unauthenticated remote exploitation, posing severe risk to traffic management infrastructure operators.

Updated Jul 31, 2026 · CVSS 9.8

cve-2026-44101ocppev-chargingunauthenticated-accessagent-relevantiotcritical-infrastructuredenial-of-serviceinformation-disclosure

CVE-2026-44101 is a critical missing-authentication vulnerability in the CHARX OCPP Agent service used to manage backend connections for EV charging infrastructure. An unauthenticated remote attacker can reconfigure the backend connection, leading to denial-of-service conditions and disclosure of confidential data, with a CVSS score of 9.8.

Updated Jul 31, 2026 · CVSS 9.8

outageavailabilityanthropicclaudeapi-disruptionagent-relevantthird-party-dependency

Anthropic experienced a worldwide service disruption affecting Claude and its underlying API, causing requests to fail with '529 Overloaded' errors. This is an availability incident rather than a malicious attack, but it disrupts any downstream applications, agents, or tools that depend on Claude's API for inference.

Updated Jul 30, 2026

icsotsiemensdenial-of-serviceplc-simulationcritical-manufacturingcwe-770

Siemens SIMATIC S7-PLCSIM Advanced is affected by a denial-of-service vulnerability (CVE-2026-54429) caused by improper handling of high-volume multicast network traffic, which can exhaust memory resources and crash the application. An unauthenticated attacker on the local network segment can trigger this condition when a specific project configuration is active, requiring manual restart to recover.

Updated Jul 30, 2026 · CVSS 7.4

sbomsupply-chainpolicyguidancesoftware-transparencyrisk-managementagent-relevant

CISA, NSA, FBI, and international partners published updated 2026 guidance defining the minimum elements for a Software Bill of Materials, replacing the 2021 NTIA baseline. This is a policy/standards update rather than an active threat, intended to strengthen software supply chain transparency and risk management across industries.

Updated Jul 30, 2026

wordpressplugin-vulnerabilityrceunauthenticatedeval-injectioncms-security

The Admin and Site Enhancements (ASE) Pro plugin for WordPress, versions up to 8.9.0, contains a critical unauthenticated remote code execution vulnerability. Attackers can exploit weak nonce/CAPTCHA enforcement and unsanitized repeater row keys spliced into an eval() call to execute arbitrary code on the server, provided the site uses the [post_cf_form] shortcode on a public page.

Updated Jul 30, 2026 · CVSS 9.8

hard-coded-credentialsrcewildflyhealthcareeol-softwaredefault-credentialsunauthenticated-access

Care Everywhere Gateway 14.3.10 ships with a bundled WildFly 8.2.0.Final management console that uses hard-coded, identical credentials across all installations, exposing an administrative interface on port 20990 to unauthenticated attackers. Successful exploitation allows deployment of a malicious WAR file, resulting in remote code execution as the Windows machine account. The affected 14.x.x branch has been end-of-life since 2017 and no patch exists for this version line.

Updated Jul 30, 2026 · CVSS 9.8