authentication bypass

BigTech Companies

Check Point SmartConsole zero-day actively exploited in attacks

Check Point has released a patch for CVE-2026-16232, a critical authentication bypass zero-day vulnerability in its SmartConsole GUI that is…

Read More »
Business

BeyondTrust warns of critical remote access software flaws

BeyondTrust has issued an urgent advisory for two critical vulnerabilities in its Remote Support and Privileged Remote Access platforms that…

Read More »
Business

SimpleHelp bug CVE-2026-48558 used to deploy Djinn Stealer malware

Attackers are exploiting CVE-2026-48558, an authentication bypass in SimpleHelp RMM, to deploy Djinn Stealer malware across Windows, macOS, and Linux…

Read More »
AI & Tech

Check Point VPN Flaw Exploited: PoC and Details Released

WatchTowr researchers have published a technical deep dive and detection tool for CVE-2026-50751, a critical authentication bypass in Check Point’s…

Read More »
BigTech Companies

Check Point ties VPN zero-day exploits to Qilin ransomware group

Check Point patched a critical zero-day vulnerability (CVE-2026-50751) in its Remote Access VPN and Mobile Access products that allows unauthenticated…

Read More »
BigTech Companies

Palo Alto VPN zero-day exploited in attacks (CVE-2026-0257)

Palo Alto Networks issued a security advisory on May 13 revealing that an authentication bypass vulnerability (CVE-2026-0257) in its firewall…

Read More »
BigTech Companies

FortiClient EMS flaw exploited by hackers to deploy infostealers

Cybercriminals are exploiting CVE-2026-35616, an authentication bypass vulnerability in FortiClient Enterprise Management Server (EMS), to deploy a new credential stealer…

Read More »
BigTech Companies

Active Exploitation of cPanel Vulnerability CVE-2026-41940 Underway

Attackers are actively exploiting the cPanel authentication bypass vulnerability (CVE-2026-41940) to deploy "Sorry" ransomware, which encrypts files with a .sorry…

Read More »
Business

Critical Auth Bypass Flaw Found in Progress MOVEit Automation

Progress Software has issued an urgent advisory for a critical authentication bypass vulnerability (CVE-2024-5806, CVSS 9.1) in MOVEit Automation's SFTP…

Read More »
Artificial Intelligence

Linux kernel LPE flaw, cPanel 0-day exploited for months

A nine-year-old Linux kernel privilege escalation flaw (CVE-2026-31431) and a critical cPanel authentication bypass (CVE-2026-41940) were actively exploited, with proof-of-concept…

Read More »
Business

Critical cPanel flaw exploited in mass ransomware attacks

A critical authentication bypass vulnerability in cPanel (CVE-2026-41940) is being actively exploited in mass ransomware campaigns, with attackers using a…

Read More »
Business

Active cPanel Bug Exploited by Hackers on Millions of Sites

A critical authentication-bypass vulnerability (CVE-2026-41940) in cPanel and WebHost Manager (WHM) allows attackers to remotely seize full control over affected…

Read More »
BigTech Companies

Device Code Phishing Attacks Jump 37x with New Kits

A massive 37.5x surge in device code phishing attacks has occurred this year, exploiting a legitimate OAuth feature designed for…

Read More »
BigTech Companies

Cisco IMC auth bypass grants attackers admin access

Cisco has patched a critical authentication bypass flaw (CVE-2026-20093) in its Integrated Management Controller, allowing unauthenticated attackers to gain administrative…

Read More »
BigTech Companies

HPE Issues Critical Alert for AOS-CX Admin Password Reset Flaw

HPE has released critical security patches for its Aruba AOS-CX operating system, addressing multiple vulnerabilities including a severe authentication bypass…

Read More »
Business

Cisco SD-WAN Zero-Day Exploited Since 2023 (CVE-2026-20127)

A sophisticated threat actor has been exploiting a zero-day authentication bypass flaw (CVE-2026-20127) in Cisco's Catalyst SD-WAN Controller since at…

Read More »
BigTech Companies

Fortinet Mitigates Critical FortiCloud SSO Zero-Day Before Patch

A critical authentication bypass flaw (CVE-2026-24858) in Fortinet's FortiCloud SSO was actively exploited, allowing attackers to gain administrative control over…

Read More »
Business

Fortinet Patches Critical FortiCloud SSO Zero-Day Under Attack

Fortinet has patched a critical zero-day vulnerability (CVE-2026-24858) that allowed attackers to bypass authentication and gain unauthorized administrative access to…

Read More »
Business

6,000+ SmarterMail Servers Vulnerable to Hijacking

A critical authentication bypass vulnerability (CVE-2026-23760) in SmarterMail email servers allows attackers to reset administrator passwords and take full control…

Read More »
Business

Fortinet Critical Auth Bypass Flaw Remains Unpatched

A critical Fortinet SSO vulnerability (CVE-2025-59718) is being actively exploited via a bypass of the initial patch, allowing attackers to…

Read More »