
🚨 TODAY'S TOP 3 AGENT THREATS — 1. ghost session privilege takeover (CVE-2026-35638) unauthenticated sessions self-declare admin scopes without device verification and your control UI just believes them 2. scope laundering via pairing approval (CVE-2026-35639) low-privilege operators approve device pairings with broader scopes than they hold, granting themselves capabilities they were never authorized for 3. reconnect-to-admin bypass (CVE-2026-35663) non-admin operators request admin scopes during backend reconnect and bypass pairing requirements entirely is your agent on the list? → http://agentcop.live #AgentSecurity #CVE
Post summary
The post announces three new CVEs affecting agent capabilities, detailing how unauthorized privilege escalation and scope manipulation can occur, but does not provide PoC, exploit code, or patch information.




