Zero-Day & Actively Exploited Vulnerabilities

Other conventional threat types

Showing 221–240 of 270 threats, newest first

agent-relevantbrowser-extensionai-agentclaude-for-chromeanthropicprivilege-escalationdata-exposurerogue-extension

Security researchers found that Claude for Chrome, Anthropic's browser-based AI agent, can be manipulated by any other malicious browser extension capable of injecting a script into claude.ai. This allows a rogue extension to trigger Claude's authenticated agent actions, silently reading a victim's Gmail, Google Docs (including comments), and Calendar without direct user consent for that specific action. The flaw is related to but distinct from the previously disclosed 'ClaudeBleed' issue, sharing the same rogue-extension prerequisite but differing in the scope of accessible data.

Updated Jul 15, 2026

SAPNetWeaverABAPmemory-corruptionout-of-bounds-writeenterprise-softwarepatch-tuesday

SAP has patched a critical out-of-bounds write vulnerability (CVE-2026-44747, CVSS 9.9) in NetWeaver Application Server ABAP that allows an authenticated attacker to trigger memory corruption, potentially exposing or modifying sensitive business data. The flaw was addressed as part of SAP's July 2026 security update cycle alongside other vulnerabilities.

Updated Jul 15, 2026 · CVSS 9.9

microsoftpatch-tuesdayzero-dayactive-exploitationwindowsvulnerability-managementagent-relevant

Microsoft's July 2026 Patch Tuesday addressed 622 CVEs, its largest release on record and more than triple the prior high, including two zero-day vulnerabilities confirmed to be under active exploitation. The advisory was informed by incident responders, indicating real-world attack activity preceded the patches. Organizations should prioritize immediate patching given the scale of the release and confirmed in-the-wild abuse.

Updated Jul 15, 2026

SonicWallSMA1000zero-dayVPNremote-accessedge-deviceexploited-in-the-wild

SonicWall has disclosed that two vulnerabilities in its SMA1000 Secure Mobile Access appliances are being actively exploited as zero-days. The company has released security updates and is urging all customers to patch immediately to prevent further compromise.

Updated Jul 15, 2026

CISAKEVSonicWallSSRFcode-injectionMicrosoftActive-DirectorySharePointfederalBOD-26-04agent-relevant

CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities Catalog, affecting SonicWall SMA1000 appliances (SSRF and code injection) and Microsoft Active Directory Federation Services and SharePoint Server (access control and authentication bypass issues). These flaws are being actively exploited in the wild and pose significant risk to federal and enterprise networks, with BOD 26-04 mandating rapid remediation for FCEB agencies.

Updated Jul 15, 2026

sonicwallsma1000code-injectioncisa-kevremote-accessvpnprivileged-attackercommand-execution

CVE-2026-15410 is a code injection vulnerability in SonicWall SMA1000 Appliances that allows an authenticated remote attacker with administrator privileges to execute arbitrary OS commands. The flaw has been added to CISA's Known Exploited Vulnerabilities catalog, indicating confirmed active exploitation in the wild. Organizations using SMA1000 for secure remote access are urged to remediate under an accelerated timeline.

Updated Jul 15, 2026

sharepointprivilege-escalationcisa-kevunauthenticatedon-premisesexploited-in-the-wild

CVE-2026-56164 is a missing authentication for critical function vulnerability in Microsoft SharePoint Server that allows an unauthorized, remote attacker to elevate privileges over the network. CISA has added this CVE to its Known Exploited Vulnerabilities (KEV) catalog with an aggressive three-day remediation deadline, indicating active exploitation in the wild. Organizations running on-premises SharePoint Server deployments should treat this as an urgent patching priority.

Updated Jul 15, 2026

CISA-KEVactive-exploitationprivilege-escalationADFSidentity-infrastructureactive-directoryagent-relevant

CVE-2026-56155 is a known-exploited privilege escalation vulnerability in Microsoft Active Directory Federation Services (ADFS) caused by insufficient granularity of access control. It allows an authorized but low-privileged attacker to elevate privileges locally, potentially leading to compromise of federated identity infrastructure. CISA has added it to the Known Exploited Vulnerabilities catalog with a remediation deadline of July 28, 2026.

Updated Jul 15, 2026

cve-2026-61498command-injectionunauthenticated-rceweb-applicationvitec-flamingoroot-privilege-escalation

A critical unauthenticated OS command injection vulnerability exists in Vitec Flamingo 4.12.2's graph generation endpoint, allowing remote attackers to execute arbitrary commands with root privileges. The flaw stems from unsanitized GET parameters being passed directly into shell execution functions, combined with insecure passwordless sudo configuration on the web server. Given the CVSS score of 9.8 and lack of authentication requirement, this is highly likely to be mass-exploited by opportunistic attackers and botnets once a public PoC emerges.

Updated Jul 14, 2026 · CVSS 9.8

gawkinteger-overflowheap-corruptionmemory-corruptionlinuxgnu-utilsdenial-of-serviceagent-relevant

A critical integer overflow vulnerability in gawk's builtin.c allows attackers to trigger memory exhaustion and corrupt heap metadata with attacker-controlled bytes, affecting versions 5.4.0 and below. Given gawk's ubiquity as a core text-processing utility on Linux/Unix systems, this vulnerability poses risk to any system, script, or automated pipeline that invokes gawk for data transformation.

Updated Jul 14, 2026 · CVSS 9.1

os-command-injectionrouteriotunauthenticated-rcefastcgipublic-exploit

A critical unauthenticated OS command injection vulnerability affects the Comfast CF-WR631AX V3 router firmware up to version 2.7.0.8, exploitable remotely via the system_wl_upload_pic_file function in the webmgnt FastCGI backend. A public exploit exists, and the vendor has not responded to disclosure, leaving affected devices permanently exposed to compromise.

Updated Jul 14, 2026 · CVSS 9.8

agent-relevantai-assistantprivilege-escalationrcecredential-theftmessaging-app-exploitopenclaw

Security researchers disclosed a chained exploit involving three now-patched vulnerabilities in the OpenClaw personal AI assistant that could be triggered via WhatsApp messages to achieve credential theft, privilege escalation, and arbitrary code execution on the host system. The attack chain leverages the assistant's integration with messaging platforms as an entry point, ultimately compromising the underlying host running the AI agent.

Updated Jul 13, 2026 · CVSS 8.8

zimbraxssstored-xssemail-securitywebmailrceunpatched

Zimbra has issued an advisory for a critical stored cross-site scripting vulnerability in its Classic Web Client that can be triggered by specially crafted emails, allowing attackers to execute malicious scripts within a victim's active session. No CVE identifier has been assigned yet, but customers are urged to apply updates immediately.

Updated Jul 12, 2026

sharefilestorage-zone-controllerfile-sharingon-premisescredible-threatprogress-software

Progress Software has issued an urgent advisory urging ShareFile customers running on-premises Storage Zone Controllers to immediately shut down their servers due to a credible, unspecified external security threat. No CVE or technical details have been publicly disclosed yet, but the severity of the recommendation (full shutdown) suggests a serious, potentially actively exploited vulnerability. Organizations using ShareFile Storage Zone Controllers should treat this as an active incident and act on vendor guidance without delay.

Updated Jul 12, 2026

agent-relevantprompt-injectionLLM-tool-abuseRCEarbitrary-file-writeprivilege-escalationAI-agent-framework

PraisonAI, an AI agent framework, contains a critical vulnerability in its AICoder component that allows attackers to abuse LLM tool-calling functionality to write files anywhere on the filesystem and execute arbitrary commands with root privileges. Exploitation can occur via malicious prompt injection through the chat interface, requiring no prior authentication or system access in many deployments. Given the CVSS score of 9.9, this represents a full system compromise vector for any organization running affected PraisonAI versions.

Updated Jul 12, 2026 · CVSS 9.9

sql-injectioncql-injectionpraisonairagvector-databaseagent-relevantcve-2026-60090

PraisonAI versions prior to 4.6.78 contain an unvalidated dimension parameter in the PGVector and Cassandra knowledge-store create_collection() functions, allowing attackers to inject arbitrary SQL/CQL into the generated DDL statement. Any caller able to influence collection creation—including downstream API consumers or agent orchestration logic—can execute destructive or data-exfiltrating database commands, resulting in a critical 9.8 CVSS-rated vulnerability.

Updated Jul 12, 2026 · CVSS 9.8

path-traversalrceidedeveloper-toolsjetbrainsagent-relevantsupply-chain-risk

A critical path traversal vulnerability in JetBrains IntelliJ IDEA allows remote code execution through manipulation of project workspace ID handling. With a CVSS score of 9.6, this flaw could allow attackers to execute arbitrary code on developer workstations, potentially via malicious project files or shared workspace configurations.

Updated Jul 12, 2026 · CVSS 9.6

ssrfxxexsdcloud-metadatakubernetescredential-theftllm-guardrailsagent-relevant

A critical SSRF vulnerability in the guardrails-detectors component allows remote attackers to submit malicious XSD schemas that trigger out-of-band requests to internal services. Exploitation can expose cloud metadata credentials, Kubernetes API tokens, MinIO endpoints, and local files such as service account tokens, enabling further lateral movement and privilege escalation.

Updated Jul 12, 2026 · CVSS 9.3

u-bootbootloaderfirmwareembedded-systemsrcedossupply-chainiotagent-relevant

Security researchers at Binarly disclosed six new vulnerabilities in U-Boot, the widely used open-source bootloader found in routers, IoT devices, and data-center server management chips (BMCs). Four flaws can cause denial-of-service crashes, while two allow arbitrary code execution if an attacker can present a malicious boot image to the device before the OS loads. Exploitation requires local or supply-chain-level access to the boot process, but successful attacks grant persistence below the operating system, making detection and remediation difficult.

Updated Jul 11, 2026

sharefileprogress-softwarestorage-zone-controllerfile-transferactive-exploitationvendor-advisoryenterprise-storage

Progress Software has urgently instructed ShareFile customers to shut down Windows servers hosting Storage Zone Controllers in response to a credible external security threat. The company has proactively disabled access to affected accounts while investigating with internal and external security teams, though no CVE or technical exploit details have been publicly disclosed yet. This mirrors past Progress Software incidents (e.g., MOVEit) where file-transfer products were mass-exploited via zero-days.

Updated Jul 11, 2026