Tag

#authentication bypass

13 published stories tagged with authentication bypass.

highDefensive GuidanceJul 28, 2026·2 min read

Brute force attacks bypass connection delays to target MikroTik RouterOS API credentials

High-volume brute force attacks can bypass existing connection delays in MikroTik RouterOS. Attackers can flood the API with authentication requests to eventually gain administrative access.

criticalExploited VulnerabilitiesJul 23, 2026·3 min read

Attackers bypass Check Point authentication to seize full administrative control of management servers

A critical authentication bypass vulnerability in Check Point's management products is being exploited in the wild.

highRansomwareJul 21, 2026·3 min read

Qilin ransomware group exploits critical Palo Alto VPN authentication bypass for network access

The Qilin ransomware gang is actively exploiting a critical authentication bypass in Palo Alto Networks PAN-OS GlobalProtect.

criticalExploited VulnerabilitiesJul 21, 2026·2 min read

Unauthenticated attackers can forge credentials to gain full administrative control of Siemens Opcenter X

A critical flaw in Siemens Opcenter X allows anyone on the network to forge their own credentials and take over administrative accounts.

highData BreachesJul 20, 2026·2 min read

Unauthorized access to Estée Lauder HR systems exposes financial accounts through Oracle flaw

An unauthorized third party gained access to Estée Lauder's HR management systems via a vulnerability in Oracle E-Business Suite.

criticalExploited VulnerabilitiesJul 14, 2026·2 min read

Critical SharePoint Authentication Bypass Enables Unauthenticated Remote Code Execution via Network Exploitation

A critical authentication bypass in Microsoft SharePoint allows attackers to circumvent security features over a network.

criticalExploited VulnerabilitiesJul 8, 2026·3 min read

Undocumented Tenda firmware backdoor allows unauthorized administrative access via specific password bypass

A critical undocumented backdoor has been discovered in multiple Tenda firmware versions, allowing anyone with a specific password to bypass standard login procedures.

criticalExploited VulnerabilitiesJul 6, 2026·2 min read

Attackers can bypass authentication to gain direct access to BeyondTrust remote support appliances

🚨 A critical authentication bypass in BeyondTrust Remote Support and Privileged Remote Access allows attackers to jump directly into the appliance.

highExploited VulnerabilitiesJun 2, 2026·6 min read

Palo Alto GlobalProtect CVE-2026-0257 Is No Longer Theoretical, Exploitation Has Reached Unpatched VPN Edges

CVE-2026-0257 is a PAN-OS GlobalProtect authentication bypass that can let an unauthenticated attacker establish an unauthorized VPN connection when authentication override is configured unsafely.

criticalSecurity AdvisoryMay 8, 2026·4 min read

Brief: Progress MOVEit Automation Critical Authentication Bypass Fixed

Progress fixed a critical authentication bypass vulnerability in MOVEit Automation. NVD describes the issue as allowing authentication bypass, and reporting says remote unauthenticated attackers can exploit it in low-complexity attacks.

criticalSecurity AdvisoryMay 8, 2026·4 min read

Defender Guidance: Progress MOVEit Automation Critical Authentication Bypass Fixed

Progress fixed a critical authentication bypass vulnerability in MOVEit Automation. NVD describes the issue as allowing authentication bypass, and reporting says remote unauthenticated attackers can exploit it in low-complexity attacks.

criticalSecurity AdvisoryMay 8, 2026·4 min read

Detection Notes: Progress MOVEit Automation Critical Authentication Bypass Fixed

Progress fixed a critical authentication bypass vulnerability in MOVEit Automation. NVD describes the issue as allowing authentication bypass, and reporting says remote unauthenticated attackers can exploit it in low-complexity attacks.

criticalSecurity AdvisoryMay 8, 2026·4 min read

Risk Brief: Progress MOVEit Automation Critical Authentication Bypass Fixed

Progress fixed a critical authentication bypass vulnerability in MOVEit Automation. NVD describes the issue as allowing authentication bypass, and reporting says remote unauthenticated attackers can exploit it in low-complexity attacks.