Tag
#Authentication Bypass
17 published stories tagged with Authentication Bypass.
Unauthenticated attackers can hijack WordPress administrator accounts via miniOrange SAML 2.0 plugin flaws
Attackers are exploiting critical flaws in the miniOrange SAML 2.0 Single Sign-On plugin to hijack WordPress accounts, including administrators.
Hard-coded credentials and unauthenticated flaws expose ANDRITZ HIPASE-250 process data and workstations
Critical vulnerabilities in the ANDRITZ HIPASE-250 system allow unauthenticated attackers to steal passwords, view live process data, and suppress audit logs.
Unauthenticated attackers exploit SharePoint vulnerability to bypass authentication and hijack administrative accounts
Attackers are actively exploiting a critical authentication bypass in Microsoft SharePoint. This flaw allows unauthenticated remote users to impersonate site users or administrators and modify data.
Attackers can hijack N-central accounts through an authentication bypass vulnerability
N-able has released an urgent hotfix for N-central to address a high-severity authentication bypass vulnerability. Attackers can potentially take over accounts in unpatched instances.
Brute force attacks bypass connection delays to target MikroTik RouterOS API credentials
High-volume brute force attacks can bypass existing connection delays in MikroTik RouterOS. Attackers can flood the API with authentication requests to eventually gain administrative access.
Attackers bypass Check Point authentication to seize full administrative control of management servers
A critical authentication bypass vulnerability in Check Point's management products is being exploited in the wild.
Qilin ransomware group exploits critical Palo Alto VPN authentication bypass for network access
The Qilin ransomware gang is actively exploiting a critical authentication bypass in Palo Alto Networks PAN-OS GlobalProtect.
Unauthenticated attackers can forge credentials to gain full administrative control of Siemens Opcenter X
A critical flaw in Siemens Opcenter X allows anyone on the network to forge their own credentials and take over administrative accounts.
Unauthorized access to Estée Lauder HR systems exposes financial accounts through Oracle flaw
An unauthorized third party gained access to Estée Lauder's HR management systems via a vulnerability in Oracle E-Business Suite.
Critical SharePoint Authentication Bypass Enables Unauthenticated Remote Code Execution via Network Exploitation
A critical authentication bypass in Microsoft SharePoint allows attackers to circumvent security features over a network.
Undocumented Tenda firmware backdoor allows unauthorized administrative access via specific password bypass
A critical undocumented backdoor has been discovered in multiple Tenda firmware versions, allowing anyone with a specific password to bypass standard login procedures.
Attackers can bypass authentication to gain direct access to BeyondTrust remote support appliances
🚨 A critical authentication bypass in BeyondTrust Remote Support and Privileged Remote Access allows attackers to jump directly into the appliance.
Palo Alto GlobalProtect CVE-2026-0257 Is No Longer Theoretical, Exploitation Has Reached Unpatched VPN Edges
CVE-2026-0257 is a PAN-OS GlobalProtect authentication bypass that can let an unauthenticated attacker establish an unauthorized VPN connection when authentication override is configured unsafely.
Brief: Progress MOVEit Automation Critical Authentication Bypass Fixed
Progress fixed a critical authentication bypass vulnerability in MOVEit Automation. NVD describes the issue as allowing authentication bypass, and reporting says remote unauthenticated attackers can exploit it in low-complexity attacks.
Defender Guidance: Progress MOVEit Automation Critical Authentication Bypass Fixed
Progress fixed a critical authentication bypass vulnerability in MOVEit Automation. NVD describes the issue as allowing authentication bypass, and reporting says remote unauthenticated attackers can exploit it in low-complexity attacks.
Detection Notes: Progress MOVEit Automation Critical Authentication Bypass Fixed
Progress fixed a critical authentication bypass vulnerability in MOVEit Automation. NVD describes the issue as allowing authentication bypass, and reporting says remote unauthenticated attackers can exploit it in low-complexity attacks.
Risk Brief: Progress MOVEit Automation Critical Authentication Bypass Fixed
Progress fixed a critical authentication bypass vulnerability in MOVEit Automation. NVD describes the issue as allowing authentication bypass, and reporting says remote unauthenticated attackers can exploit it in low-complexity attacks.