#authentication bypass
25 stories taggedauthentication bypass.

Ivanti Fixes Critical Security Holes in Three Business Software Products
Six flaws in Ivanti Neurons for ITSM could let attackers run malicious code on affected systems from anywhere on the internet. Two other products, Sentry and EPMM, received fixes for authentication bypass bugs.

Fortinet Fixes Two Critical Security Flaws That Let Attackers Bypass Logins Entirely
One bug hides secret keys inside web code anyone can read. Another turns a Chrome extension into a traffic spy. Neither needed a password.

Cisco firewall manager flaw rated 10 out of 10 is under active attack
A perfect-score bug in Cisco's Secure Firewall Management Center lets attackers take full control without a password. Evidence suggests exploitation started weeks before Cisco confirmed it.

Attackers Are Actively Exploiting a Perfect-10 WSO2 Authentication Flaw
A critical vulnerability in the WSO2 API platform, rated as severe as it gets, lets criminals forge login credentials and walk into the back end of enterprise systems. Exploitation began on September 13.

Cisco's Network Gatekeeper Has a Perfect-10 Flaw and Hackers Are Already Inside
A zero-day in Cisco Identity Services Engine lets anyone on the internet walk past the login screen entirely. Federal agencies have three days to patch. There is no workaround.

Hackers Are Already Breaking Into Software Stores Using a Flaw Disclosed Three Days Ago
A critical security hole in JFrog Artifactory, a platform used by thousands of companies to store and ship software, is being actively exploited just 72 hours after its public disclosure.

Working Exploit Published for Cleo Harmony Flaw That Ransomware Gangs Already Love
A newly discovered flaw in the Cleo Harmony file-transfer application lets attackers break in and take control without a password. A working exploit is already public, and Cl0p used a different Cleo bug to hit major organisations just months ago.

22,000 Microsoft Exchange servers still open to mailbox takeover flaw
A patched but widely ignored bug lets attackers read, send and download every user's email. Exploit code is already circulating.

Hackers Are Already Exploiting a Critical Flaw in JFrog Artifactory
A severe authentication weakness in a tool used by software teams worldwide was patched on August 28. Within days, attackers had found a way to use it to give themselves full administrator access.

Hackers Chain Two miniOrange WordPress Plugin Bugs to Log in as Admin
Paid editions of the popular SAML single sign-on plugin were quietly patched in July but never got a public warning, and now attackers are forging login sessions on sites that never updated.

Atlassian and Splunk Push Patches for More Than 250 Flaws, Including Critical Bugs
Two major software vendors dropped sweeping security updates this week. Here is what changed, what could go wrong without the fix, and what ordinary users should know.

Citrix Patches Critical Login-Bypass Flaw in NetScaler, Attacks Expected Soon
A security hole rated 9.3 out of 10 lets criminals walk straight past the login screen on widely used corporate network gear. Patches are out now, and researchers say exploitation is a matter of when, not if.

Fortinet Patches Eight Flaws, Including Two That Let Attackers Log In Without Real Credentials
Two high-severity bugs in Fortinet's security products could let criminals talk their way past login screens they should never be able to reach.

SharePoint Flaw Lets Attackers Log In as Anyone. Microsoft Patches CVE-2026-55040.
Researchers used an AI agent to help chain bugs in Microsoft SharePoint into an unauthenticated takeover. The flaw carries a CVSS score of 9.1 and affects three server editions still widely used across government and enterprise.

SAP Patches Four Critical Flaws on August 2026 Patch Day, Including a Perfect-10 Severity Bug
A maximum-severity authentication bypass in SAP Commerce Cloud leads a batch of 28 new security fixes. Organisations running SAP software should patch now.