Tag

#authentication bypass

21 stories taggedauthentication bypass.

Photoreal news-editorial style, 16:9 framing, edge-to-edge composition
Vulnerabilities

Fortinet Patches Eight Flaws, Including Two That Let Attackers Log In Without Real Credentials

Two high-severity bugs in Fortinet's security products could let criminals talk their way past login screens they should never be able to reach.

3 min read
Photoreal editorial image of a dimly lit server room with rack-mounted enterprise servers, one status LED glowing amber, subtle blue ambient light, focus on cab
Vulnerabilities

SharePoint Flaw Lets Attackers Log In as Anyone. Microsoft Patches CVE-2026-55040.

Researchers used an AI agent to help chain bugs in Microsoft SharePoint into an unauthenticated takeover. The flaw carries a CVSS score of 9.1 and affects three server editions still widely used across government and enterprise.

4 min read
Close-up, editorial news-photography style, of a single illuminated server rack panel in a darkened data centre, with amber and red indicator lights casting a f
Vulnerabilities

SAP Patches Four Critical Flaws on August 2026 Patch Day, Including a Perfect-10 Severity Bug

A maximum-severity authentication bypass in SAP Commerce Cloud leads a batch of 28 new security fixes. Organisations running SAP software should patch now.

3 min read
Extreme close-up of a glowing smartphone screen showing a software update progress bar, deep shadows around the device, cool blue-white light from the screen il
Vulnerabilities

Microsoft and Apple Rush Out Patches for Flaws That Let Attackers In Without a Password

Several of the Microsoft bugs score a perfect 10 out of 10 for severity. Apple quietly fixed a flaw that lets someone access your screen without logging in.

3 min read
Photoreal editorial image, 16:9 full-frame edge-to-edge composition
Vulnerabilities

CISA flags N-able N-central bug as actively exploited, orders federal fix

The remote monitoring platform used by thousands of IT providers carries an authentication bypass that attackers are already using in the wild.

3 min read
Full-frame edge-to-edge photoreal close-up of intertwined fiber-optic cables glowing with cool blue light, threaded through a darkened server rack, one strand v
Vulnerabilities

N-able confirms hackers seized N-central servers through a login-bypass flaw

The remote-management platform's first patch didn't hold. A second fix, in build 2026.3.1.7, closes CVE-2026-18577.

3 min read
Aerial view of a vast modern highway interchange at dusk, concrete lanes splitting and merging with precision, motion-blur streaks of vehicle lights tracing pat
AI Security

The 'RufRoot' Flaw: Why Patching Alone Won't Fix This AI Security Hole

A perfect-severity bug in the Ruflo AI platform let anyone walk in without a password, steal credentials, and quietly poison the system's memory, and the poisoning can linger even after the patch is applied.

3 min read
Full-frame photoreal editorial shot of a dimly lit server room with a single rack unit highlighted by a red status LED, blurred network cables in the foreground
Vulnerabilities

Check Point's Admin Console Has a Critical Flaw That Hands Attackers the Keys to Everything

A security hole in Check Point's management software lets criminals walk in without a password and rewrite the rules of an entire network. Ten organisations have already been hit.

4 min read
A server rack in a dimly lit data center, glowing amber and blue indicator lights reflecting off brushed-metal chassis surfaces, shallow depth of field on the f
Vulnerabilities

Hackers Are Actively Exploiting a Flaw in Check Point Security Software

A newly discovered hole in Check Point's network management tools let attackers log in as administrators without a password. Real attacks were already happening before the patch arrived.

3 min read
Full-frame photoreal editorial shot of a laptop screen showing a generic file-archive dialog with a compressed folder icon highlighted, warm desk lamp light, ou
Vulnerabilities

Check Point Rushes Fix for SmartConsole Flaw Already Being Exploited

A critical authentication bypass in Check Point's management console let attackers waltz past the login screen. The vendor confirms real-world attacks are already happening.

3 min read
Photoreal news-editorial style, 16:9, close-up of glowing server rack hardware in a dark data center, cool blue and amber lighting, shallow depth of field, no p
Vulnerabilities

Seven Security Flaws Fixed in VMware Avi Load Balancer, One Rated Critical

Broadcom has patched a critical flaw that lets attackers break into a core networking component without a password, plus six more serious bugs found by two outside researchers.

3 min read
Full-frame photoreal editorial image of a dimly lit server room with a single rack door left ajar, blue and amber indicator lights glowing on network appliances
Vulnerabilities

BeyondTrust patches two critical bugs that let attackers walk past the login screen

The remote-access vendor rushed out fixes for four flaws in its Remote Support and Privileged Remote Access products, two of which allow unauthenticated attackers to reach powerful admin accounts under certain configurations.

3 min read
Full-frame photoreal editorial shot of a dimly lit server room aisle with rows of glowing amber and blue rack lights, one open cabinet door revealing exposed ca
Identity & Access

Hackers Race to Exploit Gitea Flaw That Lets Anyone Log In as Admin

A missing check in Gitea's Docker images let attackers claim any username by adding a single header. Sysdig says probing began within days of the patch.

3 min read
Vulnerabilities

SimpleHelp OIDC Bypass Gets Weaponized: TaskWeaver and Djinn Stealer Land on Unpatched Servers

An unauthenticated auth bypass scoring a perfect 10.0 is dropping two new malware families on remote-support boxes that nobody remembered were internet-facing.

2 min read
Vulnerabilities

Palo Alto Confirms In-the-Wild Abuse of GlobalProtect Auth Bypass (CVE-2026-0257)

An unknown actor is exploiting a 7.8-rated authentication bypass in PAN-OS portals and gateways to slip past GlobalProtect logins.

2 min read
© 2026 Threat Vectr