Skip to content

Topic

Authentication Bypass Flaws

Defects that allow network access without valid credentials, often via faulty state or credential-validation logic.

Current stories

security12 publishers

Attackers reach admin on Cisco Catalyst SD-WAN Manager by encoding one URL character

Cisco says attackers are exploiting CVE-2026-76504, a 9.8-rated flaw that gives unauthenticated requests admin access to the Catalyst SD-WAN Manager API. Every configuration is affected, leaving exposed on-premises Managers needing an out-of-cycle upgrade and a check for earlier intrusion.

Perspective Coverage

12 publishers
Builder
Builder 14%
Operator
Operator 76%
Investor
Investor 10%

Reality

Evidence85
Adoption
Insufficient
Hype gap+10
Incentives40
Confidence80
build1 publisher

Attackers use a URI-encoding bug to run Cisco SD-WAN Manager's API as admin

Cisco says attackers are exploiting CVE-2026-76504, a 9.8 CVSS flaw that lets anyone reaching SD-WAN Manager's API act as admin with no credentials. Managers patched for the May and June flaws still need the new releases, because those fixes predate this one.

Publishers:dev.to

Reality

Evidence55
Adoption
Insufficient
Hype gap+5
Incentives
Insufficient
Confidence55
security5 publishers

NetScaler auth bypass at 9.3: the box is the perimeter, so patch it this week

CVE-2026-19490 lets an unauthenticated attacker past NetScaler gateway and AAA virtual servers. Rapid7 has seen no exploitation yet and expects it shortly.

Perspective Coverage

5 publishers
Builder
Builder 14%
Operator
Operator 73%
Investor
Investor 13%

Reality

Evidence78
Adoption62
Hype gap+10
Incentives38
Confidence75
security5 publishers

Two miniOrange SAML bugs under attack, and 30,000 paid installs were never told

Patchstack says attackers are chaining CVE-2026-61979 and CVE-2026-15981 to mint WordPress admin sessions. Only the free edition got an advisory; Standard needs 17.0.6.

Perspective Coverage

5 publishers
Builder
Builder 32%
Operator
Operator 56%
Investor
Investor 12%

Reality

Evidence70
Adoption30
Hype gap+15
Incentives
Insufficient
Confidence68
security10 publishers

Chained PaperCut flaws let unauthenticated requests load attacker Java into the server process

Huntress has seen exploitation in two customer environments. One flaw hands over PaperCut's configuration without a login, the second turns that configuration into a class loader, so patching and config review are one job.

Perspective Coverage

10 publishers
Builder
Builder 27%
Operator
Operator 60%
Investor
Investor 13%

Reality

Evidence85
Adoption70
Hype gap−10
Incentives40
Confidence78
security6 publishers

Unauthenticated attackers can forge admin tokens on default self-managed Artifactory installs

CVE-2026-82329 is reported as a pre-auth authentication bypass in JFrog Artifactory's Access microservice, and it reaches every dependency your builds pull from the platform. One publisher, no vendor advisory.

Publishers:bleepingcomputer.comcvereports.comdocs.jfrog.comscworld.comsecurityweek.comthehackernews.com

Perspective Coverage

6 publishers
Builder
Builder 28%
Operator
Operator 63%
Investor
Investor 9%

Reality

Evidence62
Adoption
Insufficient
Hype gap+20
Incentives55
Confidence64

Earlier coverage

  1. Delinea's 2 September hotfixes all land inside the new SAML impersonation range

    Build · September 17, 2026 · 1 publisher

  2. CVE-2026-24858 let attackers log into Fortinet devices registered to other customers

    Security · September 17, 2026 · 1 publisher

  3. LiteLLM's MCP endpoint answered a failed key check with an empty auth object

    Build · September 16, 2026 · 1 publisher

  4. Any Kestra API path ending in /configs skipped Basic Authentication

    Build · September 15, 2026 · 1 publisher

  5. mySCADA myPRO Manager takes privileged commands from anyone who can reach its API

    Security · September 15, 2026 · 1 publisher

  6. Unauthenticated request pulls plaintext admin credentials off Digital Watchdog VMAX recorders

    Security · September 15, 2026 · 1 publisher

  7. Attackers lifted the cluster join key out of self-hosted Artifactory

    Build · September 11, 2026 · 1 publisher

  8. Two chained N-central bugs hand an unauthenticated caller a System administrator account

    Security · September 8, 2026 · 1 publisher

  9. Anthropic says everyday infostealers are lifting live Claude sessions off victim machines

    Security · September 4, 2026 · 1 publisher

  10. Exploit attempts hit NetScaler's August auth bypass 15 days after Citrix shipped the fix

    Security · September 4, 2026 · 1 publisher

  11. A query string smuggled into the Host header makes Starlette skip authentication

    Build · September 4, 2026 · 1 publisher

  12. Pillar chains a 9.1 SSRF to self-minted session IDs in Grafana's MCP server

    Security · September 3, 2026 · 1 publisher

  13. Dovecot's 2.4 settings refactor drops the SQL escape its own passdb asked for

    Build · September 2, 2026 · 1 publisher

  14. Hive's SAML validator hands out a session to any Bearer token you forge

    Build · August 30, 2026 · 1 publisher

  15. Xiiaozet's LK100W lets an unauthenticated caller switch on its admin services

    Security · August 27, 2026 · 1 publisher

  16. Honeypots logged a SharePoint JWT bypass hunting for a Business Data Catalog sink

    Build · August 27, 2026 · 1 publisher

  17. Apple patches a network-reachable Screen Sharing auth bypass in macOS Tahoe 26.6.1

    Security · August 16, 2026 · 1 publisher

  18. Unauthenticated root on macOS Screen Sharing: CVE-2026-65400 is already dropping miners

    Build · August 14, 2026 · 1 publisher