Find a story
Search Spins
Search titles, summaries, and missing voices across published articles — press releases, announcements, and media coverage.
12 results for “authentication bypass”
Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks
Cisco confirmed active exploitation of a critical authentication bypass flaw (CVE-2026-20079) in its Secure Firewall Management Center software, posing immediate risk to enterprise network security.
Sep 10, 2026
Hackers exploit critical JFrog Artifactory flaw to forge admin tokens
Hackers are actively exploiting a critical authentication bypass flaw (CVE-2026-82329) in JFrog Artifactory to forge administrative tokens, enabling unauthorized system control.
Sep 3, 2026
Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks
Over 21,000 publicly exposed Microsoft Exchange servers remain unpatched against CVE-2024-21410, a critical authentication bypass flaw enabling full mailbox compromise — posing immediate, widespread risk to organizational email integrity and data confidentiality.
Sep 2, 2026
Hackers exploit macOS Screen Sharing flaw to deploy Monero miner
Hackers are actively exploiting a known macOS Screen Sharing authentication bypass vulnerability to deploy Monero cryptocurrency miners, prompting an official warning from the Netherlands' NCSC.
Aug 14, 2026
Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
Attackers are actively exploiting a critical Microsoft SharePoint authentication bypass vulnerability (CVE-2026-55040, CVSS 9.1) after public release of PoC code, despite Microsoft having patched it in July 2026 Patch Tuesday.
Aug 13, 2026
Attackers Exploit N-able Patch Bypass Flaw on RMM Servers
N-able disclosed a newly discovered authentication bypass vulnerability (CVE-2026-18577) in its RMM platform that grants attackers full administrator access, following prior exploitation of related flaws.
Aug 4, 2026
N-able warns of N-central auth bypass flaw exploited in attacks
N-able disclosed an actively exploited authentication bypass flaw (CVE-2026-18577) in its N-central remote monitoring and management platform, exposing hosted and on-premises deployments to unauthorized access.
Aug 3, 2026
N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete
N-able disclosed that attackers exploited an authentication bypass vulnerability (CVE-2026-18577) in its N-central remote monitoring and management platform to gain unauthorized administrative access, and that its initial patch was incomplete — requiring a second fix released on August 2.
Aug 3, 2026
JetBrains warns of critical TeamCity remote code execution flaw
JetBrains disclosed a critical remote code execution vulnerability in its TeamCity On-Premises CI/CD server due to an authentication bypass, posing immediate exploitation risk to self-hosted users.
Jul 31, 2026
Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape
Broadcom released security patches for three critical VMware vulnerabilities—including authentication bypass, remote code execution, and VM escape—across ESX, vCenter, Workstation, and Fusion, posing severe enterprise infrastructure risks.
Jul 29, 2026
Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass
A critical authentication bypass vulnerability (CVE-2026-16232, CVSS 9.3) in Check Point’s SmartConsole login process has been actively exploited in the wild, and researchers have now released a public proof-of-concept exploit.
Jul 29, 2026
Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
Check Point released emergency patches for an actively exploited authentication bypass vulnerability (CVE-2026-16232, CVSS 9.3) in SmartConsole that grants full administrative access without credentials.
Jul 23, 2026