Tag

#authentication bypass

25 stories taggedauthentication bypass.

A corporate office IT environment showing three different server terminals and software consoles, with critical vulnerability badges displayed on each, and patc
Vulnerabilities

Ivanti Fixes Critical Security Holes in Three Business Software Products

Six flaws in Ivanti Neurons for ITSM could let attackers run malicious code on affected systems from anywhere on the internet. Two other products, Sentry and EPMM, received fixes for authentication bypass bugs.

3 min read
A security login screen with multiple authentication methods displayed, one visibly bypassed with code visible in the browser developer tools panel open beside
Vulnerabilities

Fortinet Fixes Two Critical Security Flaws That Let Attackers Bypass Logins Entirely

One bug hides secret keys inside web code anyone can read. Another turns a Chrome extension into a traffic spy. Neither needed a password.

3 min read
A cybersecurity operations center with Cisco Secure Firewall Management Center interface displayed on a large screen, a perfect 10
Vulnerabilities

Cisco firewall manager flaw rated 10 out of 10 is under active attack

A perfect-score bug in Cisco's Secure Firewall Management Center lets attackers take full control without a password. Evidence suggests exploitation started weeks before Cisco confirmed it.

4 min read
An enterprise data center with highlighted API server infrastructure, digital locks breaking open, and credential tokens flowing through network pathways as ala
Vulnerabilities

Attackers Are Actively Exploiting a Perfect-10 WSO2 Authentication Flaw

A critical vulnerability in the WSO2 API platform, rated as severe as it gets, lets criminals forge login credentials and walk into the back end of enterprise systems. Exploitation began on September 13.

4 min read
Photoreal news-editorial photograph, 16:9 framing, full-frame edge-to-edge composition
Vulnerabilities

Cisco's Network Gatekeeper Has a Perfect-10 Flaw and Hackers Are Already Inside

A zero-day in Cisco Identity Services Engine lets anyone on the internet walk past the login screen entirely. Federal agencies have three days to patch. There is no workaround.

3 min read
A software repository server facility with glowing rack-mounted hardware and network cables, while a security alert banner scrolls across a monitoring station's
Vulnerabilities

Hackers Are Already Breaking Into Software Stores Using a Flaw Disclosed Three Days Ago

A critical security hole in JFrog Artifactory, a platform used by thousands of companies to store and ship software, is being actively exploited just 72 hours after its public disclosure.

4 min read
A cybersecurity analyst's workstation with multiple windows open showing file-transfer application code, vulnerability databases, and a functioning exploit code
Vulnerabilities

Working Exploit Published for Cleo Harmony Flaw That Ransomware Gangs Already Love

A newly discovered flaw in the Cleo Harmony file-transfer application lets attackers break in and take control without a password. A working exploit is already public, and Cl0p used a different Cleo bug to hit major organisations just months ago.

3 min read
A server rack in dim lighting with warning indicators illuminated, network cables organized but vulnerable-looking, data streams flowing across screens showing
Vulnerabilities

22,000 Microsoft Exchange servers still open to mailbox takeover flaw

A patched but widely ignored bug lets attackers read, send and download every user's email. Exploit code is already circulating.

3 min read
A software deployment dashboard displaying administrator access controls being progressively elevated, authentication logs showing unauthorized privilege escala
Vulnerabilities

Hackers Are Already Exploiting a Critical Flaw in JFrog Artifactory

A severe authentication weakness in a tool used by software teams worldwide was patched on August 28. Within days, attackers had found a way to use it to give themselves full administrator access.

3 min read
A computer screen showing a WordPress admin dashboard being accessed, with shadowy hands reaching through the monitor toward the login interface
Vulnerabilities

Hackers Chain Two miniOrange WordPress Plugin Bugs to Log in as Admin

Paid editions of the popular SAML single sign-on plugin were quietly patched in July but never got a public warning, and now attackers are forging login sessions on sites that never updated.

4 min read
A software company's website or dashboard visible on screen with security advisory banners prominently displayed, showing patch release notifications and update
Vulnerabilities

Atlassian and Splunk Push Patches for More Than 250 Flaws, Including Critical Bugs

Two major software vendors dropped sweeping security updates this week. Here is what changed, what could go wrong without the fix, and what ordinary users should know.

3 min read
Enterprise network gateway hardware with warning lights active and security personnel examining the device while patch deployment screens glow on adjacent works
Vulnerabilities

Citrix Patches Critical Login-Bypass Flaw in NetScaler, Attacks Expected Soon

A security hole rated 9.3 out of 10 lets criminals walk straight past the login screen on widely used corporate network gear. Patches are out now, and researchers say exploitation is a matter of when, not if.

3 min read
A security operations center with multiple screens displaying firewall software interfaces, with red alert notifications and authentication bypass warnings high
Vulnerabilities

Fortinet Patches Eight Flaws, Including Two That Let Attackers Log In Without Real Credentials

Two high-severity bugs in Fortinet's security products could let criminals talk their way past login screens they should never be able to reach.

3 min read
A SharePoint server interface with authentication mechanism broken, showing unauthorized access pathways and AI chain-attack visualization flowing through multi
Vulnerabilities

SharePoint Flaw Lets Attackers Log In as Anyone. Microsoft Patches CVE-2026-55040.

Researchers used an AI agent to help chain bugs in Microsoft SharePoint into an unauthenticated takeover. The flaw carries a CVSS score of 9.1 and affects three server editions still widely used across government and enterprise.

3 min read
SAP software dashboard displaying August 2026 patch notifications with four critical vulnerabilities highlighted in red, perfect-ten severity authentication byp
Vulnerabilities

SAP Patches Four Critical Flaws on August 2026 Patch Day, Including a Perfect-10 Severity Bug

A maximum-severity authentication bypass in SAP Commerce Cloud leads a batch of 28 new security fixes. Organisations running SAP software should patch now.

3 min read
© 2026 Threat Vectr