
🚨 TODAY'S TOP 3 AGENT THREATS — 1. reconnect privilege escalation (CVE-2026-35663) non-admin operators self-grant admin privileges during backend reconnect by bypassing pairing requirements 2. scope boundary bypass via gateway routes (CVE-2026-35669) plugin HTTP routes incorrectly mint operator.admin scope regardless of caller permissions, handing attackers elevated privileges 3. session reset access control failure (CVE-2026-35660) attackers with operator.write can reset admin sessions via /reset endpoint, hijacking administrative control is your agent on the list? → http://agentcop.live #AgentSecurity #CVE
Post summary
The post announces three new CVEs affecting agent software, detailing privilege escalation, scope bypass, and access control flaws, but includes no PoC, exploit, patch, or evidence of active exploitation.



