#authentication bypass
25 stories taggedauthentication bypass · page 2 of 2.

Microsoft and Apple Rush Out Patches for Flaws That Let Attackers In Without a Password
Several of the Microsoft bugs score a perfect 10 out of 10 for severity. Apple quietly fixed a flaw that lets someone access your screen without logging in.

CISA flags N-able N-central bug as actively exploited, orders federal fix
The remote monitoring platform used by thousands of IT providers carries an authentication bypass that attackers are already using in the wild.

N-able confirms hackers seized N-central servers through a login-bypass flaw
The remote-management platform's first patch didn't hold. A second fix, in build 2026.3.1.7, closes CVE-2026-18577.

The 'RufRoot' Flaw: Why Patching Alone Won't Fix This AI Security Hole
A perfect-severity bug in the Ruflo AI platform let anyone walk in without a password, steal credentials, and quietly poison the system's memory. The poisoning can linger even after the patch is applied.

Check Point's Admin Console Has a Critical Flaw That Hands Attackers the Keys to Everything
A security hole in Check Point's management software lets criminals log in without a password and rewrite the rules of an entire network. Ten organisations have already been hit.

Hackers Are Actively Exploiting a Flaw in Check Point Security Software
A newly discovered hole in Check Point's network management tools let attackers log in as administrators without a password. Real attacks were already happening before the patch arrived.

Check Point Rushes Fix for SmartConsole Flaw Already Being Exploited
A critical authentication bypass in Check Point's management console let attackers walk past the login screen. The vendor confirms real-world attacks are already happening.

Seven Security Flaws Fixed in VMware Avi Load Balancer, One Rated Critical
Broadcom has patched a critical flaw that lets attackers break into a core networking component without a password, plus six more serious bugs found by two outside researchers.

Hackers Race to Exploit Gitea Flaw That Lets Anyone Log In as Admin
A missing check in Gitea's Docker images let attackers claim any username by adding a single header. Sysdig says probing began within days of the patch.

SimpleHelp OIDC Bypass Gets Weaponized: TaskWeaver and Djinn Stealer Land on Unpatched Servers
An unauthenticated auth bypass scoring a perfect 10.0 is dropping two new malware families on remote-support boxes that nobody remembered were internet-facing.