Cisco's identity appliance is being hit through an API endpoint that never checked who was asking.
WatchTowr reports attackers are minting admin tokens through the critical JFrog Artifactory auth bypass patched August 28.
Two unauthenticated bugs in the miniOrange SAML plugin let attackers log in as any WordPress user.
Citrix fixed a CVSS 9.3 authentication bypass in NetScaler ADC and Gateway that attackers are expected to exploit quickly.
Attackers are exploiting a critical SharePoint authentication bypass days after Rapid7 shipped proof-of-concept code.
Unit 42 details three ways malware can abuse Chrome's synced passkey flows to hijack accounts.
Attackers used an authentication bypass in N-able N-central to reach managed endpoints, and the vendor's first fix did not block…
A CVSS 9.5 Rails Active Storage flaw lets unauthenticated attackers read arbitrary server files through crafted image uploads.