< ciso
brief />
Tag Banner

All news with #authentication bypass tag

451 articles · page 3 of 23

PaperCut issues second emergency patch for exploited flaws

🛡️ PaperCut released a second emergency security update after researchers found multiple bypasses of the initial fix for actively exploited vulnerabilities in PaperCut NG/MF. The company disclosed two CVEs—CVE-2026-81578 (auth bypass, 8.8) and CVE-2026-82078 (unsafe dynamic class-loading, 9.4)—that can be chained for remote code execution. The updated Emergency Patch Release 2 provides additional hardening and is available for versions 24–26 on Windows, Linux, and macOS; administrators are urged to install it and restrict web interface access.
read more →

Attackers Chain Two PaperCut Flaws to Achieve RCE

🛡️ Huntress and watchTowr reported attackers chaining two recently patched PaperCut vulnerabilities to bypass authentication and achieve remote code execution. PaperCut released a second emergency patch with additional hardening after disclosure of CVE-2026-81578 and CVE-2026-82078. Observed activity includes execution of Base64-encoded commands and deployment of a cross-platform Java .class file used for reconnaissance and cleanup.
read more →

Ubiquiti fixes three maximum-severity vulnerabilities

🔒 Ubiquiti released patches for three maximum-severity vulnerabilities affecting UniFi applications and OS. The flaws include a remote exploit in the UniFi Protect Application, a CRLF injection (CVE-2026-77550) that can bypass authentication on UniFi OS devices, and a command injection in the UniFi Talk VoIP system (CVE-2026-77554). Patches are available in UniFi Protect 7.2.105+, UniFi Talk 5.3.2+, and UniFi OS Server 5.1.21+.
read more →

miniOrange SAML plugin under active exploitation

🔒 Patchstack and DigitalOcean reported active exploitation attempts against miniOrange SAML 2.0 Single Sign On, where two unauthenticated flaws allow attackers to authenticate as any WordPress user, including admins. The issues are tracked as CVE-2026-61979 and CVE-2026-15981 and have been fixed in recent Standard edition updates. Owners are urged to update immediately due to available PoC code and observed opportunistic scanning from multiple IPs.
read more →

Unpatched Calix NAT bypass risk exposes internal devices

🔒 An unpatched authentication flaw in Calix GS7 XGS (GS5239XG) residential gateways running EXOS/6.6.47 lets remote unauthenticated attackers create and manipulate port-forwarding rules via the MiniUPnPd control endpoint on TCP port 5000. Researcher Brian Khan Quintana reported the issue as CVE-2026-75501 after failed vendor notification and worked with CERT/CC for disclosure. Exploitation can permanently open firewall rules that expose internal cameras, NAS, IoT devices, and admin interfaces; users are advised to disable UPnP or contact their ISP if the setting is locked.
read more →

miniOrange SAML plugin under active auth bypass attacks

🔐 Attackers are exploiting two critical authentication bypass flaws in the miniOrange SAML 2.0 Single Sign On WordPress plugin to forge SAML responses and gain administrator access. The plugin, used to integrate WordPress with corporate IdPs like Microsoft Entra ID, Okta, and Google Workspace, improperly accepts the incoming signature algorithm and mishandles OpenSSL verification errors. Fixes were released in July for free and paid editions, but incomplete vendor disclosure left many paid installations unpatched and exposed to exploitation.
read more →

Critical Keycloak password reset vulnerability patched

🔒 Red Hat and the Keycloak project released patches to fix a critical flaw (CVE-2026-18963) that allows an unauthenticated remote attacker to take over user accounts by forcing a password reset. Upstream Keycloak users should update to 26.7.2 (released Aug 19, 2026); Red Hat build customers must apply fixes for 26.4.15 and 26.6.6. Red Hat rates the issue 9.1 CVSS and recommends disabling the "Forgot password" feature as a temporary mitigation while upgrading.
read more →

CISA orders federal patching for TrueConf flaws

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has directed federal agencies to urgently patch two actively exploited critical vulnerabilities in the self-hosted TrueConf Server communications platform. The flaws, tracked as CVE-2026-72529 and CVE-2026-72530, allow unauthenticated remote code execution through a missing authentication function and complex code-injection attacks. CISA added both issues to its KEV catalog and mandated fixes within two weeks due to significant risk to the federal enterprise.
read more →

Cisco issues patches for Crosswork and Secure Workload

🔒 Cisco released security updates for its Crosswork platforms and Secure Workload software following an internal review. Four critical flaws affecting Crosswork (including SQL injection and missing authentication) were fixed in Crosswork 7.2.1-SP. Five vulnerabilities impacting Secure Workload (SaaS and on-premises) were remediated in releases 3.10.9.1 and 4.0.4.16. Customers are urged to apply updates despite no known active exploitation.
read more →

Citrix issues critical patches for NetScaler gateways

🔒 Citrix has released critical updates for customer-managed NetScaler ADC and NetScaler Gateway to address two serious vulnerabilities: a memory overflow that can cause unpredictable behavior or denial of service, and an authentication bypass that permits pre-authentication access. Supported on-premises builds and certain deployments are affected while Citrix-managed services have been updated; cloud marketplace images may still need manual replacement. Security experts urge immediate emergency patching, credential rotation, session termination, and active hunting due to the high risk of rapid weaponization against internet-facing gateways.
read more →

Citrix NetScaler critical authentication bypass patched

🛡️ Citrix released patches for two NetScaler ADC and Gateway flaws, including a critical authentication bypass affecting certain appliance configurations. The issues impact customer-managed NetScaler ADC/Gateway, some FIPS/NDcPP builds, and SecurAccess ZTNA Hybrid using customer-managed instances, but not Citrix-managed cloud services. Administrators should verify configurations and apply updates for affected versions to mitigate risk.
read more →

Citrix issues urgent NetScaler security update advisory

🔒 Citrix warned customers to immediately patch two NetScaler vulnerabilities impacting NetScaler Gateway and NetScaler ADC appliances. The most severe, CVE-2026-19490, can allow remote attackers to bypass authentication when SAML action is configured on certain AAA, Auth, or VPN virtual servers. The other, CVE-2026-19489, is a high-severity memory overflow that can enable remote DoS when SIP ALG is enabled on large-scale NAT group configurations. Citrix published recommended firmware builds and urged immediate upgrades for affected deployments.
read more →

Researchers Demonstrate 'Zombie Card' Revival Attack

🔒 Researchers at UMass Amherst demonstrated the "Zombie Card" attack that can revive expired Visa contactless cards by rewriting the terminal-facing expiration date over NFC, without breaking cryptography. The technique requires proximity or possession of the card and a relay between card and POS; success depends on issuer and EMV kernel. Tests across multiple banks and kernels produced mixed outcomes, and the team presented the work at USENIX Security 2026.
read more →

AIT-GUI flaws could let unauthenticated actors command craft

🔒 Security researchers at Cycode disclosed a critical chain of flaws in AIT-GUI, the browser-based operator console for NASA/JPL's AMMOS Instrument Toolkit, allowing unauthenticated attackers to issue arbitrary commands to the instrument and spacecraft command bus. Tracked as GHSA-p9r8-2q67-fp86 and rated 9.4 (CVSS v3.1), the issues affect AIT-GUI ≤2.5.1 and were addressed in 2.5.2 on August 12, 2026. The defects include missing authentication, absent CSRF protection, and path traversal on state-changing routes, enabling POST-based command, script execution, and sequence abuse when reachable.
read more →

Critical AIT‑GUI Flaw Allows Remote Command Execution

🔒 A critical vulnerability in NASA's open-source AIT-GUI ground control software could let unauthenticated actors issue spacecraft and instrument commands, execute server-side scripts, and run command sequences. Disclosed by Cycode researcher Yuval Elbar on August 18 and tracked as GHSA-p9r8-2q67-fp86 (CVSS 9.4), the flaw affects versions through 2.5.1 and was fixed in 2.5.2. The issue stems from an API that listens on all interfaces, lacks authentication/CSRF protection, and allows unsafe filesystem path construction on execution endpoints.
read more →

Critical GitLab GraphQL Flaw Allows Remote Project Changes

🔒 GitLab released out-of-cycle security updates on August 17, 2026, to fix a critical GraphQL vulnerability (CVE-2026-19478) that could let unauthenticated attackers remotely modify or delete public projects and user data. The patches apply to self-managed instances in versions 18.11.11, 19.0.8, 19.1.6, and 19.2.4; hosted GitLab.com and Dedicated are already patched. A second, High-severity issue (CVE-2026-19650) addresses a CSRF-related GraphQL multiplex handling flaw requiring user interaction.
read more →

Critical WordPress plugin flaw exposes admin accounts

🔒 More than 40,000 WordPress sites were exposed by an authentication bypass in the User Profile Builder plugin. Tracked as CVE-2026-15826 with a 9.8 CVSS score, versions up to 3.16.4 are affected. Wordfence identified a type confusion in the registration/auto-login flow that can convert a failed registration into user ID 1, enabling generation of an admin authentication token. The vendor released version 3.16.5 on July 16; site owners should update immediately.
read more →

SafePal data breach exposes nearly 40,000 orders

🔒 SafePal reports a data breach affecting about 39,798 customers after an authorization flaw in an order-tracking plug-in was exploited to steal order information. The exposed data includes names, emails, shipping addresses, phone numbers, and purchase details for orders placed between March 2, 2025, and April 11, 2026. SafePal says sensitive wallet credentials, payment card numbers, and government IDs were not exposed and that it has fixed the vulnerability, notified affected customers, and launched a verification tool. A threat actor is now claiming to sell the stolen data on a cybercrime forum, and the company warns of targeted phishing and social engineering attempts.
read more →

macOS Screen Sharing flaw exploited to install miner

🔒 The Netherlands' NCSC warns that a macOS Screen Sharing authentication bypass (CVE-2026-65400) is being actively exploited after public exploit code appeared. The flaw affects the built-in VNC-based Screen Sharing service (TCP 5900) and allows network attackers to authenticate without valid credentials. Apple fixed the issue in macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9; affected users should update or disable Screen Sharing in System Settings.
read more →

PoC for SharePoint JWT Bypass Now Used in Attacks

🔒 A Rapid7 proof-of-concept for a critical SharePoint JWT authentication bypass (CVE-2026-55040) is already being weaponized in attacks, researchers warn. Microsoft patched the flaw in its July 2026 updates for SharePoint Enterprise Server 2016 and SharePoint Server 2019 and cautioned that exploitation can disclose files and modify data. CISA has issued guidance urging teams to avoid exposing SharePoint servers and to apply hardening measures.
read more →