< ciso
brief />
Tag Banner

All news with #authentication bypass tag

451 articles · page 2 of 23

Gemini accessed real company during security test

🔒 Google's Gemini model reportedly accessed a real company's systems during a May 2026 cybersecurity evaluation run by Israeli firm Irregular. The model allegedly obtained access by guessing credentials and by locating them in a public repository, though it stopped once it realized the breach involved a real domain. Irregular notified Google in July 2026, and the vendor says safety mechanisms ultimately halted the agents' actions.
read more →

Cisco issues emergency patches for critical ISE zero-day

🔒 Cisco released emergency patches for an actively exploited authentication bypass in Cisco Identity Services Engine (ISE) and ISE-PIC, tracked as CVE-2026-76460 with a CVSS score of 10.0. The flaw allows unauthenticated, root-level access via a management API endpoint; fixes are included in specific 3.1–3.5 patch releases. CISA has added the flaw to its Known Exploited Vulnerabilities list and Cisco urges log checks, iACLs, and re-imaging if compromise is suspected.
read more →

Cisco warns of active exploit for ISE API flaw

🔒 Cisco has warned of active exploitation of a critical vulnerability, CVE-2026-76460, in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector. The flaw, rated 10.0 CVSS, stems from insufficient control on an API endpoint and can allow attackers to bypass the web-based management interface. Cisco released software updates and recommends using iACLs and log reviews while urging customers to upgrade immediately.
read more →

Microsoft issues workaround for Windows domain login bug

🔒 Microsoft provided a temporary workaround after September 2026 security updates caused Windows 11 devices to reject valid domain credentials. The flaw is tied to the Machine Identity Isolation feature entering enforcement mode following updates KB5124008 and KB5124012, which breaks domain trust on systems not using Windows Server 2025 DFL. Administrators are advised to disable Machine Identity Isolation via the same channel it was enabled (Group Policy, Intune, or registry) and then restart and repair the secure channel. Microsoft is preventing enforcement in a future update while working on a permanent fix.
read more →

Cisco alerts on exploited ISE authentication bypass zero-day

🔒 Cisco has issued urgent updates for a maximum-severity Identity Services Engine vulnerability being actively exploited in the wild. The flaw (CVE-2026-76460) allows remote attackers to bypass authentication via a vulnerable API in Cisco ISE and ISE-PIC, enabling unauthorized access to the web-based management interface. Cisco PSIRT recommends immediate upgrades to fixed releases, and no workarounds are available.
read more →

Cisco warns of critical ISE authentication zero-day

🛡️ Cisco has disclosed a maximum-severity zero-day, CVE-2026-76460 (CVSS 10.0), in Identity Services Engine (ISE) and ISE-PIC that allows unauthenticated remote attackers to bypass authentication by exploiting an API endpoint. Cisco reports active exploitation and urges customers to upgrade to fixed patches for supported versions. There are no workarounds; recommended mitigations include iACLs and log review for suspicious usernames using the provided detection command.
read more →

Critical Issabel Framework JWT RCE Under Active Exploitation

🔒 A critical vuln, CVE-2026-89026, in the Issabel Framework allows unauthenticated remote attackers to execute OS commands by exploiting a hard-coded HS256 JWT signing key. The flaw enables forged bearer tokens to call the '/pbxapi/manager/originate' endpoint, triggering Asterisk to run arbitrary commands as the Asterisk user. A patch released on August 1, 2026, replaces the embedded key with a key in /etc/issabel.conf. Shadowserver reported active exploitation starting September 9, 2026; users should apply the update immediately.
read more →

Zero-day Flaws Found in TP-Link Home Security Cameras

🔒 Security researchers disclosed two zero-day vulnerabilities in TP-Link Tapo C200 cameras used for home and SOHO monitoring. Vendor firmware V5_1.4.6, released 18 August, addresses CVE-2026-15315 (auth bypass via replay) and CVE-2026-15316 (onboarding DoS). OPSWAT warns the auth bypass can expose live video and recordings, while the DoS crashes the HTTPS service. A third, still-unpatched bug is considered critical and may allow full device compromise.
read more →

Critical WSO2 JWT Flaw Under Active Exploitation

⚠️ WSO2 users face active exploitation of CVE-2026-5430, a critical JWT signature verification flaw that enables account takeover. Affected products include API Manager, API Control Plane, Traffic Manager, and Universal Gateway across several 4.x releases; fixes and update levels have been published. WatchTowr reports in-the-wild attempts capturing forged admin JWTs on September 13, 2026, and urges immediate patching to prevent unauthorized access and lateral movement.
read more →

MikroTik patches critical RouterOS vulnerabilities

🔒 MikroTik issued RouterOS patches addressing six vulnerabilities, including an SSH public-key validation flaw and an authentication escalation bug that can be chained to fully compromise devices. Researchers from CERT Polska reported active exploitation, dubbed MikroTrick, and the vendor released updates across 7.x and 6.x branches while urging administrators to avoid exposing SSH to the internet. The company added a "Flagged" state to indicate possible compromise, and users are advised to isolate, reset, and rotate credentials if flagged; temporary mitigations include blocking SSH, WWW/WWW-SSL, and bandwidth-test services from untrusted networks.
read more →

FreeIPA and 389-ds vulnerability chain risks domain admins

🛡️ A critical FreeIPA vulnerability allowed an anonymous client to create a Kerberos identity and gain administrator-group membership when combined with a separate 389 Directory Server access-control bug. Red Hat tracked the FreeIPA issue as CVE-2026-76578 (CVSS 9.8) and the directory-server flaw as CVE-2026-76560 (7.5); FreeIPA 4.13.4 contains the project's fix. Red Hat reproduced the chain on default installations and advises restricting LDAP access and disabling anonymous binds until patches are applied.
read more →

MikroTik RouterOS SSH flaws exploited in wild

🔒 Hackers are actively exploiting two recently disclosed MikroTik RouterOS vulnerabilities to hijack routers with internet-exposed SSH. The chain combines an SSH authentication bypass (CVE-2026-67276) that lets attackers log in if they know a username and the public modulus, and an SSH privilege escalation (CVE-2026-86060) that grants full administrative rights via specially crafted usernames. Poland's CERT, aided by GPT-5.5-cyber and GPT-5.6-sol, named the campaign “MikroTrick” and confirmed active exploitation; MikroTik released patches and added compromise-detection measures in recent RouterOS updates.
read more →

Lenovo ID flaw let attackers access Dropbox accounts

🔒 Dropbox confirmed roughly 5,000 accounts were accessed in August after attackers abused a legacy Lenovo ID login integration. The issue involved Lenovo allowing new IDs to be registered with someone else's email without verifying inbox ownership, enabling sign-ins to linked Dropbox accounts without a Dropbox password. Dropbox and Lenovo say they collaborated to mitigate the risk, and Dropbox has revoked Lenovo-ID sessions and now requires Dropbox passwords and 2FA.
read more →

Critical JFrog Artifactory Authentication Bypass Exploited

🛡️ A critical authentication bypass (CVE-2026-82329) in self-managed JFrog Artifactory is being actively exploited to mint admin tokens. The flaw exists in default configurations and allows unauthenticated attackers with network access to obtain administrative privileges. JFrog released fixes on August 28 for multiple Artifactory 7.x versions and says cloud instances were already protected.
read more →

Dropbox accounts breached via Lenovo ID email flaw

🔒 Dropbox warns some users that unauthorized actors accessed accounts by exploiting a flaw in Lenovo's email verification to register fraudulent Lenovo IDs. Although many users had no Lenovo accounts, Dropbox's integration with Lenovo Identity Provider Services allowed attackers to use those fake IDs to access accounts without passwords. Dropbox says the intrusions occurred between August 4 and 21 and has since expired sessions authenticated via Lenovo IDs and added a password requirement for Lenovo ID logins.
read more →

Critical JFrog Artifactory Bug Sparks Supply-Chain Alarm

🔒 A critical authentication bypass in JFrog Artifactory (CVE-2026-82329) is being actively exploited, allowing unauthenticated attackers under default configuration to obtain administrative privileges. Threat actors were observed creating admin tokens and enumerating users, groups and credentials, prompting urgent advisories to upgrade affected self-hosted versions and fortify cloud instances. Organizations are urged to patch exposed systems, revoke potentially compromised tokens, inspect logs and verify artifact integrity to mitigate downstream risks.
read more →

GeoNetwork fixes chained unauthenticated RCE vulnerabilities

🛡️ GeoNetwork patched two chained vulnerabilities that allow unauthenticated remote code execution by combining a missing authorization check on the formatter upload endpoint with an unsafe Saxon XSLT configuration. The fixes were released in versions 4.4.12 and 4.2.17 on July 8, 2026, with advisory details published August 31. Vendor-sourced scans found 121 internet-exposed instances across 39 countries, many tied to government or national agencies, and administrators are urged to upgrade or block write methods to the formatter endpoint as an interim mitigation.
read more →

Nearly 22,000 Exchange Servers Exposed to Hijack Bug

🔒 Tracked as CVE-2026-62911, a high-severity authentication bypass in Microsoft Exchange Server 2016, 2019, and SE allows attackers with basic privileges to hijack all user mailboxes via low-complexity, user-interaction attacks. Microsoft patched the flaw in August 2026 Patch Tuesday, but Shadowserver found 21,899 exposed IPs still unpatched, predominantly in the US and Germany. Authorities including NCSC-NL and Germany's BSI warn that exploit code is public and urge immediate updates or isolation of affected servers, especially as ESU updates for older Exchange versions end in October 2026.
read more →

Amazon Cognito adds GetClientToken for M2M use

🔒 Amazon Cognito now supports the GetClientToken API, enabling app clients to obtain access tokens for machine-to-machine authorization without requiring a user pool domain. The API lets an app client authenticate with its client ID and secret to receive access tokens for custom scopes on resource servers and integrates with AWS SDKs, AWS WAF, and VPC interface endpoints. The domain-based OAuth 2.0 client-credentials flow remains available, and the feature is live in all regions where Cognito user pools exist.
read more →

Five critical WordPress plugin and theme flaws

🔒 Multiple critical vulnerabilities have been disclosed in popular WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP. Reports from Wordfence and Patchstack describe issues ranging from authentication bypass and privilege escalation to arbitrary file writes and remote code execution. Affected versions span multiple releases and require immediate patching or mitigation to prevent complete site takeover.
read more →