
🚨 TODAY'S TOP 3 AGENT THREATS — 1. reconnect privilege escalation (CVE-2026-35663) non-admin operators self-grant admin privileges during backend reconnect by bypassing pairing requirements 2. scope boundary bypass via gateway routes (CVE-2026-35669) plugin HTTP routes incorrectly mint operator.admin scope regardless of caller permissions, handing attackers elevated privileges 3. session reset access control failure (CVE-2026-35660) attackers with operator.write can reset admin sessions via /reset endpoint, hijacking administrative control is your agent on the list? → http://agentcop.live #AgentSecurity #CVE
Post summary
Three newly disclosed agent‐related CVEs (CVE‑2026‑35663, CVE‑2026‑35669, CVE‑2026‑35660) that allow privilege escalation and session hijacking are described, with no mention of PoC, exploit code, active exploitation, patches, or mis‑information.

