Tag
#authentication bypass
13 published stories tagged with authentication bypass.
Brute force attacks bypass connection delays to target MikroTik RouterOS API credentials
High-volume brute force attacks can bypass existing connection delays in MikroTik RouterOS. Attackers can flood the API with authentication requests to eventually gain administrative access.
Attackers bypass Check Point authentication to seize full administrative control of management servers
A critical authentication bypass vulnerability in Check Point's management products is being exploited in the wild.
Qilin ransomware group exploits critical Palo Alto VPN authentication bypass for network access
The Qilin ransomware gang is actively exploiting a critical authentication bypass in Palo Alto Networks PAN-OS GlobalProtect.
Unauthenticated attackers can forge credentials to gain full administrative control of Siemens Opcenter X
A critical flaw in Siemens Opcenter X allows anyone on the network to forge their own credentials and take over administrative accounts.
Unauthorized access to Estée Lauder HR systems exposes financial accounts through Oracle flaw
An unauthorized third party gained access to Estée Lauder's HR management systems via a vulnerability in Oracle E-Business Suite.
Critical SharePoint Authentication Bypass Enables Unauthenticated Remote Code Execution via Network Exploitation
A critical authentication bypass in Microsoft SharePoint allows attackers to circumvent security features over a network.
Undocumented Tenda firmware backdoor allows unauthorized administrative access via specific password bypass
A critical undocumented backdoor has been discovered in multiple Tenda firmware versions, allowing anyone with a specific password to bypass standard login procedures.
Attackers can bypass authentication to gain direct access to BeyondTrust remote support appliances
🚨 A critical authentication bypass in BeyondTrust Remote Support and Privileged Remote Access allows attackers to jump directly into the appliance.
Palo Alto GlobalProtect CVE-2026-0257 Is No Longer Theoretical, Exploitation Has Reached Unpatched VPN Edges
CVE-2026-0257 is a PAN-OS GlobalProtect authentication bypass that can let an unauthenticated attacker establish an unauthorized VPN connection when authentication override is configured unsafely.
Brief: Progress MOVEit Automation Critical Authentication Bypass Fixed
Progress fixed a critical authentication bypass vulnerability in MOVEit Automation. NVD describes the issue as allowing authentication bypass, and reporting says remote unauthenticated attackers can exploit it in low-complexity attacks.
Defender Guidance: Progress MOVEit Automation Critical Authentication Bypass Fixed
Progress fixed a critical authentication bypass vulnerability in MOVEit Automation. NVD describes the issue as allowing authentication bypass, and reporting says remote unauthenticated attackers can exploit it in low-complexity attacks.
Detection Notes: Progress MOVEit Automation Critical Authentication Bypass Fixed
Progress fixed a critical authentication bypass vulnerability in MOVEit Automation. NVD describes the issue as allowing authentication bypass, and reporting says remote unauthenticated attackers can exploit it in low-complexity attacks.
Risk Brief: Progress MOVEit Automation Critical Authentication Bypass Fixed
Progress fixed a critical authentication bypass vulnerability in MOVEit Automation. NVD describes the issue as allowing authentication bypass, and reporting says remote unauthenticated attackers can exploit it in low-complexity attacks.