< ciso
brief />
Tag Banner

All news with #authentication bypass tag

451 articles

SonicWall SMA1000 SSRF flaw signals broader security pattern

🔒 SonicWall disclosed CVE-2026-102255, a pre-authentication SSRF vulnerability in the SMA1000 Appliance Workplace interface rated CVSS 10.0, allowing attackers to make the appliance issue requests and reach internal functions without credentials. The company also reported three additional, lower-severity flaws and strongly urges customers to upgrade to fixed releases. SonicWall says there's no evidence of active exploitation yet, but experts warn the attack is trivial to execute and could enable remote compromise.
read more →

Critical Atlassian Data Center Arbitrary File Access

🛡️ Atlassian has disclosed a critical arbitrary file access vulnerability (CVE-2026-21589, CVSS 9.3) affecting multiple Data Center products including Bitbucket, Confluence, Jira, Bamboo, Crowd, Crucible, and Fisheye. The flaw allows unauthenticated attackers to retrieve specific files from the web application root if they know the exact path and filename. Atlassian released patches for impacted versions and recommends temporary mitigations such as removing instances from the public internet, deploying WAF rules, and applying Tomcat or urlrewrite.xml protections. Telemetry shows early exploitation attempts from a few IPs, and security researchers warn rapid scanning and mass exploitation are likely following public technical details.
read more →

SonicWall warns of max-severity SSRF in SMA1000

🔒 SonicWall issued hotfixes to address a maximum-severity server-side request forgery (SSRF) vulnerability in SMA1000 series appliances, including the 6210, 7210, and 8200v models. This flaw enables remote, unauthenticated attackers to abuse an unintended alternate access path to make the appliance issue requests on their behalf and reach internal functionality. SonicWall recommends applying the Tuesday hotfixes immediately; there is currently no evidence of active exploitation, though over 400 exposed appliances are tracked by Shadowserver.
read more →

Citrix NetScaler memory-overflow DoS vulnerability alert

⚠️ Citrix has warned of a new high-severity memory-overflow vulnerability (CVE-2026-88779) affecting NetScaler ADC and NetScaler Gateway appliances, rating it 8.7 under CVSS 4.0 and reporting observed targeted exploitation. The flaw can cause repeated denial-of-service conditions when SAML authentication is configured and used with Gateway or AAA virtual servers. Citrix provided fixed build numbers and a temporary virtual-patching mitigation via Global Deny List signatures, and warned that affected customers who already patched earlier in the week may need to upgrade again. CISA added the vulnerability to its KEV catalog with an October 7 remediation deadline for US federal agencies.
read more →

Critical Dell CSM Flaws Allow Full Administrative Access

🔒 Dell released updates to fix multiple critical flaws in Container Storage Modules (CSM) that allow unauthenticated attackers to gain administrative control, escalate privileges, or forge tokens. Affected versions are all prior to 1.17.0, and the fixes are included in 1.18.0. Dell urges immediate updating and rotation of JWT signing secrets, as no effective mitigations exist aside from upgrading.
read more →

Critical Zero-Day in Cisco Catalyst SD‑WAN Manager

🔒 Cisco has released an urgent advisory for CVE-2026-76504, a critical (CVSS 9.8) authentication bypass in Cisco Catalyst SD-WAN Manager that is being actively exploited. The flaw stems from improper URI encoding handling in API session authentication, allowing unauthenticated remote attackers to gain admin-level access. Cisco and CISA urge immediate upgrades to fixed releases; no practical workaround exists, and cloud-hosted mitigations have been deployed but require customer validation.
read more →

Kiteworks fixes max-severity EPG code-injection flaw

🔒 Kiteworks released security updates addressing 126 vulnerabilities across its platform, including a max-severity code-injection flaw in the Email Protection Gateway (EPG). The issue, tracked as CVE-2026-54154, was reported via the YesWeHack bug bounty program and allowed unauthenticated remote code execution through a chain of path traversal, code injection, and missing authentication. The EPG flaw affects versions prior to 9.4.1 and is patched in 9.4.1 or later, while additional critical issues in Core and EPG were also fixed.
read more →

Cisco SD‑WAN Manager zero‑day allows admin access

🔒 Cisco fixed a critical flaw in Cisco Catalyst SD‑WAN Manager that let attackers bypass authentication via improperly handled URI encoding in HTTP requests. The vulnerability, tracked as CVE-2026-76504 with a 9.8 CVSS score, could grant administrative API privileges without credentials. Cisco has patched cloud-managed systems and released fixes for affected on‑prem releases; there is no workaround, so restricting access until upgrades are applied is advised.
read more →

CISA Adds Critical Cisco SD‑WAN Manager Flaw to KEV

🔒 CISA has added a critical authentication bypass vulnerability in Cisco Catalyst SD‑WAN Manager (CVE-2026-76504, CVSS 9.8) to its Known Exploited Vulnerabilities list after reports of active exploitation. The flaw allows an unauthenticated, remote attacker to gain admin privileges by abusing improper URI handling in HTTP requests. Cisco provided IoCs and log entries to audit, and FCEB agencies must apply fixes by October 3, 2026. Organizations are urged to upgrade to fixed releases and hunt for POST requests to URL-encoded variants of "/j_security_check".
read more →

Cisco warns of SD‑WAN authentication bypass zero‑day

🔒 Cisco released updates to address a critical zero-day in the Catalyst SD-WAN Manager (CVE-2026-76504) that is being actively exploited to gain admin privileges. The flaw affects API session-based authentication and allows unauthenticated remote access by bypassing an authentication rule via improper URI encoding. Cisco published IOCs and log locations for detection and urged customers to upgrade to fixed releases or open TAC cases for investigation. Multiple fixed releases are listed for affected versions.
read more →

France tax portal breach exposed weak access controls

🛡️ A data theft at France's tax administration (DGFIP) in June–July exposed contact and tax-related messages for roughly 350,000 individuals and 250,000 businesses after attackers used stolen staff passwords. ANSSI's report finds the incident relied on weak login protection, poor network segregation and gaps in monitoring, with the attacker scraping E-Contact and other portals via compromised accounts and partner systems. Remediations include stronger MFA, extended SIEM coverage, session revocation on password resets and blocking personal-device access to government systems.
read more →

Elementor CSRF Flaw Lets Attackers Create Admins

🔒 A high-severity CSRF vulnerability in the Elementor Website Builder (versions 4.3.0 and 4.3.1) allows an unauthenticated attacker to coerce logged-in users into performing REST API actions, including creating rogue administrator accounts. Patchstack reported the issue, which affects over 2 million installations of those versions and has a CVSS score of 8.8. The flaw stems from the Editor Events module skipping CSRF checks when "elementor/v1/events/" appears in the request URI. Elementor addressed the bug in version 4.3.2 following disclosure by researcher "Saggre," and users are urged to update immediately.
read more →

GitLab issue-email token exposes account access

🛡️ A GitLab feature that supplies a project-scoped email address to create issues embeds a long-lived token in the address, which can be used to act as the linked user across projects. Aikido Security found the token (prefixed with glimt-) is identical across project addresses for an account and bypasses IP restrictions, enabling actions like creating issues and merge requests with the account's permissions. GitLab updated wording to acknowledge merge request capabilities; Aikido recommends treating the addresses as credentials and rotating tokens if exposed.
read more →

Unpatched OnePlus flaws let installed apps gain root

🔒 A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app that requests no special permissions. Researcher Rasmus Moorats chained two vendor services to gain root: one that accepts arbitrary calls and injects text into system commands, and another that executes shell instructions when invoked as root. OnePlus confirmed the flaws in May, claimed exclusive control over disclosure, and had not released a patch when Moorats published on September 24.
read more →

Leaked GitLab email token enables commits and CI

📧 GitLab issues each user a persistent incoming-email address for filing work items; that address contains a token tied to the account and does not expire. Researchers at Aikido Security found the token is shared across a user's project addresses and allows anyone who holds the address to create issues, open merge requests by email, commit patches to branches (including main) and trigger CI/CD jobs that run as the account holder. GitLab currently does not verify the sender address, and incoming email bypasses IP allowlists and two-factor requirements.
read more →

AWS Endorses ASD Campaign to Require MFA

🔐 AWS supports the Australian Signals Directorate’s (ASD) Multi-factor authentication: Switch it on campaign and urges all customers to enable MFA. The post highlights that passwords alone are insufficient against phishing and credential-stuffing attacks and notes MFA blocks over 99% of password-based compromises. AWS describes its phased enforcement of MFA for root users across all account types and promotes phishing-resistant options like FIDO2 passkeys and security keys.
read more →

Arista issues patch for actively exploited VCO zero‑day

🔒 Arista Networks has released patches for a critical zero-day (CVE-2026-93952) actively exploited in VeloCloud Orchestrator (VCO) On‑Prem deployments. The flaw, caused by improper input validation when certificate-based Edge-to‑VCO authentication is configured, allows remote attackers to access privileged host functionality without credentials or user interaction. Arista and CISA have both flagged the issue and recommended immediate mitigation and log review.
read more →

Rogue external MFA providers can steal passwords

🔒 Security researchers at Varonis Threat Labs have demonstrated an attack, dubbed TrustSink, that lets an attacker with a highly privileged Microsoft Entra account register a rogue external MFA provider to capture users' passwords during legitimate logins. The malicious provider displays a convincing copy of Microsoft's password prompt during the MFA step, captures credentials in plaintext, then returns a valid signed token so the login completes normally. The technique requires post-compromise access to Global Administrator or Authentication Policy Administrator privileges and can persist across password resets until the rogue provider is removed.
read more →

Critical Bifrost AI gateway flaw allows remote code

🛡️ A critical vulnerability in Bifrost, an open-source AI gateway, lets unauthenticated attackers execute arbitrary commands on the gateway server via a single HTTP request when management authentication is disabled. Tracked as CVE-2026-90898 (CVSS 9.8), the flaw affects HTTP transports before transports/v2.1.0 and is exploitable by registering a stdio-type MCP client through the management API; a fix is available in v2.1.0. Operators should upgrade, enable management auth, and rotate exposed keys if the management API was reachable.
read more →

SharePoint flaw reclassified as remote code execution

🛡️ Microsoft initially labeled a SharePoint Server bug as a spoofing issue, but researcher Dinh Ho Anh Khoa's full disclosure shows it enables authenticated remote code execution. The flaw, CVE-2026-65660, affects SharePoint Server 2016, 2019, and Subscription Edition and was patched in August; the NVD assigns it an 8.8 score. Khoa's write-up details how unescaped quotes in Register directives allow arbitrary .NET class loading and execution via XamlServices.Parse().
read more →