Other Conventional Threats

Other conventional threat types

Showing 321–340 of 390 threats, newest first

fortinetforticlientemscertificate-validationinformation-disclosuremitmcve-2026-59836

CVE-2026-59836 is an improper certificate validation flaw in Fortinet FortiClientEMS affecting versions 7.2, 7.4.0-7.4.1, and 7.4.3-7.4.5, which could allow an attacker to gain access to sensitive information. The vulnerability likely enables man-in-the-middle style attacks due to insufficient validation of TLS/SSL certificates during communications.

Updated Jul 16, 2026 · CVSS 7.5

icsotbuilding-automationknxaccount-lockoutphysical-securitycisa-kev

CVE-2023-4346 is a vulnerability in the KNX Protocol's Connection Authorization Option 1 mechanism that allows an attacker to exploit an overly restrictive account lockout to purge all devices lacking additional security options and lock devices via a BCU key. This affects building automation and industrial control deployments using KNX, potentially causing denial of service and loss of device control. CISA has added this CVE to its Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild.

Updated Jul 16, 2026

ICSSCADADLL-hijackinglocal-privilege-escalationABBCWE-427critical-infrastructure

ABB disclosed CVE-2025-13162, an uncontrolled search path (DLL hijacking) vulnerability affecting Online Builder (ONB) as included in Control Builder A and 800xA for Advant Master. A local attacker with prior system access could place a malicious DLL in an unrestricted application directory to achieve arbitrary code execution on the affected node.

Updated Jul 15, 2026 · CVSS 4.4

ICSOTprivilege-escalationlinux-kernelABBcritical-infrastructureCWE-669

A high-severity local privilege escalation vulnerability (CVE-2026-31431, 'Copy Fail') affects ABB Ability Edgenius edge computing platforms due to a flaw in the Linux kernel's algif_aead cryptographic interface. A locally authenticated user or compromised container workload could exploit incorrect in-place memory operations to gain full root access on affected devices. ABB has released version 3.2.4.1 to remediate the issue.

Updated Jul 15, 2026 · CVSS 7.8

apache-kylinos-command-injectionrcecve-2026-62392unauthenticated-possibleagent-relevant

Apache Kylin versions 4 through 5.0.3 contain a critical OS command injection vulnerability where backend API job configuration parameters are passed unsanitized to the OS command line, allowing attackers to execute arbitrary commands on the host. With a CVSS score of 9.8, this flaw poses severe risk to any organization running affected Kylin instances, particularly those exposed to untrusted networks. Users should upgrade immediately to version 5.0.4, which resolves the issue.

Updated Jul 15, 2026 · CVSS 9.8

sql-injectionapache-kylindata-analyticsrag-pipelineagent-relevant

A critical SQL injection vulnerability (CVE-2026-62390) affects Apache Kylin versions 4 through 5.0.3, stemming from improper neutralization of special elements in a backend API that refreshes the table catalog. Successful exploitation could allow attackers to manipulate generated SQL queries, potentially leading to unauthorized data access, modification, or full database compromise. Users should upgrade to version 5.0.4 to remediate the issue.

Updated Jul 15, 2026 · CVSS 9.8

apache-dorisbroken-authenticationrest-apiunauthenticated-accessdenial-of-servicedata-infrastructureagent-relevant

Apache Doris versions prior to 3.1.0 expose Frontend (FE) HTTP REST administrative APIs without proper authentication enforcement, allowing unauthenticated network attackers to perform privileged administrative operations. This can lead to cluster instability, unauthorized configuration changes, or denial of service against the analytics cluster.

Updated Jul 15, 2026 · CVSS 9.1

perlregexinteger-overflowlogic-flawinput-validationagent-relevantrag-pipelinesupply-chain-risk

A flaw in Perl's regex engine (Perl_study_chunk) causes silent match corruption when an alternation pattern contains more than 65535 fixed-string branches, due to a 16-bit field overflow during trie compilation. This can produce false positive or false negative matches with no warning, undermining any security or filtering logic that relies on such patterns.

Updated Jul 15, 2026 · CVSS 9.1

joomlacmsfile-deletionunauthenticatedweb-vulnerabilityhelix-ultimate

CVE-2026-57830 is a critical vulnerability in the Helix Ultimate Joomla extension that allows unauthenticated attackers to delete arbitrary files on the underlying server. This could lead to denial of service, configuration file loss, or destruction of critical application data without requiring any authentication.

Updated Jul 15, 2026 · CVSS 9.1

credential-exposuregithubcloud-securitysecrets-managementgovernmentsupply-chaininsider-riskagent-relevant

A CISA contractor inadvertently published dozens of sensitive internal credentials, including AWS GovCloud keys, in a public GitHub repository where they remained exposed for nearly six months before external notification by a security journalist. The incident highlights systemic weaknesses in secrets management, contractor oversight, and detection capability within a federal cybersecurity agency, raising concerns about the broader public and private sector's exposure to similar risks.

Updated Jul 14, 2026

ShareFileCitrix Bleed 2ransomwareAI-assisted attacksvulnerability exploitationpatch-lagagent-relevant

This weekly recap highlights multiple concurrent threats including exploitation of ShareFile vulnerabilities, ransomware campaigns leveraging the 'Citrix Bleed 2' flaw, and a rising trend of attackers using AI coding tools to accelerate exploit development. The report underscores how unpatched, previously disclosed vulnerabilities continue to be actively exploited due to delayed remediation, and how trusted software supply chains are increasingly weaponized against their own users.

Updated Jul 14, 2026

cyberattacktaxi-industryjapaninfrastructure-shutdownincident-response

Nihon Kotsu, Japan's largest taxi operator, suffered a cyberattack that forced the company to shut down parts of its IT infrastructure. Details on the attack vector, threat actor, and data impact have not been disclosed. The incident highlights ongoing targeting of transportation and logistics companies by threat actors.

Updated Jul 14, 2026

CISAKEVCiscoCSRFvulnerability-managementfederal-agenciesnetwork-infrastructure

CISA added CVE-2008-4128, a Cross-Site Request Forgery vulnerability in Cisco IOS, to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. Federal Civilian Executive Branch agencies must remediate this per BOD 26-04, and CISA recommends all organizations prioritize patching this vulnerability on publicly exposed assets.

Updated Jul 14, 2026

gawklinuxheap-corruptioninteger-overflowdenial-of-service32-bitopen-sourceagent-relevant

A vulnerability in gawk's builtin.c (do_sub() routine) allows an integer overflow that corrupts heap metadata and objects, causing crashes on 32-bit builds of gawk version 5.4.0 and earlier. The flaw could potentially be leveraged for further exploitation beyond denial of service depending on heap layout and attacker control over input strings passed to gawk substitution functions.

Updated Jul 14, 2026 · CVSS 9.1

ImageMagickheap-overflowout-of-bounds-readimage-processingdenial-of-serviceagent-relevant

ImageMagick versions prior to 7.1.2-19 contain a heap buffer over-read in the magnify operation, triggered by an unrecognized magnify:method value. Exploitation can lead to information disclosure from adjacent heap memory or crash the process, resulting in denial of service.

Updated Jul 14, 2026 · CVSS 3.3

ciscoioscsrfnetwork-devicecisa-kevweb-management-interface

Cisco IOS 12.4 contains cross-site request forgery vulnerabilities in its HTTP-based management interface, allowing remote attackers to trick authenticated administrators into executing arbitrary privileged commands. This flaw is included in CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild. Successful exploitation could lead to full device reconfiguration or compromise of network infrastructure.

Updated Jul 14, 2026

hardware-attackfault-injectioncryptocurrencyside-channelphysical-accesswallet-security

Ledger's Donjon security team demonstrated a physical fault-injection attack using a precisely timed laser pulse against the secure chip in Tangem crypto wallet cards, allowing an attacker to reset the card's password without knowledge of the original credential. Once reset, the attacker gains full control of the wallet and can transfer out any stored funds. The attack requires specialized equipment, physical possession of the card, and cannot be remediated via software patch since it exploits hardware-level fault injection.

Updated Jul 13, 2026

non-securityproduct-newsanthropicclaude

This article is a routine product availability notice stating Anthropic has extended free access to its Claude Fable 5 model for paid subscribers until July 19. It contains no indicators of a security vulnerability, breach, or malicious activity and does not constitute a cyber threat.

Updated Jul 13, 2026

not-a-threatproduct-announcementopenaicapacity-management

This item is a routine product/operations announcement from OpenAI regarding temporary relaxation of usage limits on GPT-5.6 Sol due to surging demand. It does not describe a vulnerability, exploit, or malicious activity and carries no direct security threat.

Updated Jul 13, 2026

agent-relevantarbitrary-file-writeRAG-pipelineLLM-toolingdockerpath-traversaldenial-of-servicecrawl4ai

Crawl4AI, a popular web-crawling library used to feed content into LLM pipelines and RAG systems, contains a critical arbitrary file write vulnerability in its Docker API server's /screenshot and /pdf endpoints. Unauthenticated or low-privilege attackers can supply crafted output_path values to write files anywhere the service account can access, potentially overwriting critical server files and causing denial of service or further compromise.

Updated Jul 13, 2026 · CVSS 9.1