Silent Patch Leaves WordPress Admins Exposed
Critical MiniOrange SAML SSO flaws exploited in wild; silent patch raises risk for WordPress sites.
30 results for “authentication”
Critical MiniOrange SAML SSO flaws exploited in wild; silent patch raises risk for WordPress sites.
Threat actor Doubloon Dredger exploits Notion and device codes to steal authentication tokens, researchers say.
A critical AIT-GUI vulnerability could let attackers send commands to NASA spacecraft and instruments without authentication.
CVE-2026-15826 in User Profile Builder exposes 40,000+ WordPress sites to admin takeover.
Fortinet resolves eight flaws, including high-severity authentication bugs in FortiWeb and FortiManager.
Threat actors are exploiting a critical SharePoint authentication bypass after Rapid7 released a PoC exploit.
An Akira affiliate rebooted a victim's PC into Safe Mode, breaking its own encryptor but still stealing data.
Researchers chain AI-found flaws to gain admin on SharePoint servers, bypassing authentication entirely.
SAP's August 2026 patch batch addresses 28 flaws, including a 10/10 severity bug in Commerce Cloud that could allow attackers to bypass authentication and execute code.
Recent research shows passkey protections can be bypassed without breaking the underlying cryptography.
A critical authentication vulnerability in Dell OpenManage Server Administrator allows unauthenticated remote attackers to gain unauthorized access.
A critical authentication bypass in Azure SQL Database allows unauthorized attackers to gain elevated privileges over a network.
A cryptographic weakness in IBM Langflow OSS allows attackers to reproduce encryption keys, potentially exposing stored API keys and authentication tokens.
CISA has added an authentication bypass vulnerability in N-able N-central to its Known Exploited Vulnerabilities catalog, requiring immediate action.
Researchers identified three methods to compromise passkeys, highlighting vulnerabilities in Google's synchronization process.
A missing authentication vulnerability in OpenCode Studio versions prior to 2.4.4 allows unauthenticated attackers to steal files and delete user videos.
A missing authentication vulnerability in Krayin CRM version 2.2.4 allows remote attackers to hijack the administrator account and gain full system access.
A severe authorization flaw in the better-auth SCIM plugin allows attackers to hijack user accounts and sessions by manipulating provider ID namespaces.
A critical vulnerability in the Single Sign On For TNG WordPress plugin allows unauthenticated attackers to reset any user password and take over sites.
New data from eSentire indicates that adversary-in-the-middle phishing has bypassed standard authentication protocols at law firms.
SecurityAn overview of how interception attacks bypass traditional authentication and what defenders can do to protect their data integrity.
A missing authentication vulnerability in Spikster allows unauthenticated attackers to remotely access API routes and perform administrative actions.
A critical authentication bypass vulnerability in SolarWinds Web Help Desk allows unauthorized access for systems with SAML 2.0 enabled.
A missing authentication vulnerability in the CHARX OCPP Agent allows remote attackers to compromise backend connections, leading to data loss and outages.
A missing authentication bug in the AMMOS Instrument Toolkit allows unauthenticated attackers to control Deep Space Network communication sessions.
A missing authentication vulnerability in the AMMOS Instrument Toolkit GUI allows unauthenticated attackers to hijack sessions and issue spacecraft commands.
A critical vulnerability in the @better-auth/scim plugin allows authenticated users to hijack accounts via provider ID collisions and bypass security controls.
A chain of vulnerabilities in 9router allows unauthenticated attackers to gain full control of the host operating system via default credentials.
A critical vulnerability in Check Point's management software allows attackers to bypass authentication and control network policy.
A critical vulnerability in Auth.js and NextAuth allows attackers to intercept magic-link sign-in flows by exploiting improper Unicode normalization.