Identity & PAM - Identity and Privileged Access Management
Everything about Identity Access Management (IAM), Privileged Access Management (PAM), Multi-Factor Authentication (MFA), and access control. Expert guides by nFlo.
Topics in this hub
PAM
7 articlesPrivileged Access Management - securing privileged accounts
MFA & Authentication
11 articlesMulti-Factor Authentication and identity verification
IAM & SSO
19 articlesIdentity and Access Management, Single Sign-On
All articles about Identity & PAM
CVE-2026-78509 and CVE-2026-78510: Critical Outlook and Word Flaws — Unauthenticated Code Execution
Two flaws rated 9.8 in the most widely used Office applications. The vector is content that reaches the user anyway: a message and a document...
CVE-2026-83941: Missing Authorization in Entra ID — A Flaw You Cannot Patch Yourself
A 9.9-rated flaw in Microsoft's identity service. There is no patch to install here - it is a cloud service the vendor fixes. What remains on your side is checking what happened...
CVE-2026-19117: authentication bypass via FIDO2 registration in Delinea Secret Server
Under specific conditions an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user — in a privileged access management system...
CVE-2026-20212: unauthenticated root code execution in Cisco Nexus 9000 switches
TCP ports 43210 and 43211 of the Silicon One integration are reachable in the default Layer 3 VRF, letting an unauthenticated attacker execute code with root privileges on the switch...
CVE-2026-49869: Authentication Bypass in Kestra OSS — One endsWith and Full RCE as Root
The authentication filter checked whether the path ended with /configs. Any API path ending in that word skips authentication - and Kestra ships with script execution plugins enabled by default...
CVE-2026-59822: Authentication Bypass in LiteLLM — The AI Gateway Let Requests Through Without a Key
Failed key validation ended not in a refusal but in an empty permissions object being substituted. The request reached MCP tooling without a valid LiteLLM key...
CVE-2026-58574: Missing Authentication in Dell PowerStore Management Interface
A critical function in the Dell PowerStore management interface requires no authentication. An attacker can read information from the appliance filesystem, including administrative credentials...
CVE-2026-81578: Missing Authentication in PaperCut NG/MF - Active Exploitation (CISA KEV)
PaperCut NG/MF does not require authentication for a critical function, which lets an unauthenticated attacker remotely change part of the system configuration. The vulnerability is being actively exploited...
CVE-2026-82266: Redpanda Admin API Treats Unauthenticated Requests as Superuser
Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with authentication disabled by default, treating unauthenticated requests as coming from a superuser...
CVE-2023-49105: Authentication Bypass in ownCloud Server
An attacker who knows a victim's username can read, modify or delete any of their files without authentication, provided the victim has no signing key configured...
UniFi OS: 12 Vulnerabilities Including Authentication Bypass (CVE-2026-77550)
Ubiquiti published a bulletin covering 12 vulnerabilities in UniFi OS and UniFi applications. The most severe lets an attacker with network access bypass authentication on UniFi OS devices...
CVE-2026-63586: unauthenticated root code execution in Weidmüller IE-SR-2TX-WL routers
Weidmüller IE-SR-2TX-WL industrial security routers let an unauthenticated attacker run arbitrary commands as root — a crafted username in the HTTP Authorization header is enough...
CVE-2026-59568 and CVE-2026-59564: remote code execution and authentication bypass in Zscaler Client Connector
The Zscaler Client Connector agent contains flaws letting an unauthenticated, unprivileged user execute arbitrary code in the ZCC context and bypass authentication against the ZCC Portal...
CVE-2026-76835: authentication bypass in OAuth2 Proxy via the X-Forwarded-Uri header (no patch available)
In its default reverse-proxy configuration OAuth2 Proxy still trusts a client-supplied X-Forwarded-Uri header, letting an attacker bypass authentication and reach protected application routes...
CVE-2026-11861 and CVE-2026-13097: FreeIPA authentication bypass via Active Directory trust
Active Directory users can bypass authentication to FreeIPA services - the portal, SMB server and LDAP directory - by impersonating a client name in the Kerberos Ticket Granting Service...
CVE-2026-66794: Authentication bypass in Red Hat Multicluster Engine
Manipulating URL path segments lets an unauthenticated attacker bypass authentication and authorization checks and proxy requests to arbitrary in-cluster services...
CVE-2026-65400: macOS Screen Sharing authentication bypass — CISA deadline August 21
A state management flaw in macOS authentication allows an attacker on the same network to connect to Screen Sharing without knowing the password...
CVE-2026-75094: OS Command Injection in COMFAST CF-N1-S
A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET§ion=ptest_ssid of the component CGI Interface. This manipulation ...
CVE-2026-19478: Unauthenticated Data Modification in GitLab CE/EE
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allo...
CVE-2026-19977: Improper Authentication in EFM ipTIME A3004T
A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function httpcon_check_session_url of the component Session Validation. Performing a manipulation results in impr...
CVE-2026-74799: Unauthenticated Debug Endpoints in SiYuan
SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps without authentication when --mode flag is not set to exactly prod. Attackers can access /debug/pprof...
CVE-2026-74894: API Authentication Bypass in openssl_encrypt
openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that accepts any non-empty Bearer token string without validation. Attackers can upload ar...
CVE-2026-74901: Unauthenticated AES-CTR Fallback in openssl_encrypt
openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption failures trigger fallback to unauthenticated AES-CTR mode. Attackers can modify ...
CVE-2026-75045: Unauthenticated Database Backup Download in YouTrack
In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature...
CVE-2026-75110: Authentication Fail-Open in MemOS
MemOS is a memory operating system for LLMs and AI agents. In deployments where authentication is enabled (AUTH_ENABLED=true) but the undocumented, defaultless INTERNAL_SERVICE_SECRET environment vari...
CVE-2025-71389: unauthenticated RCE via bundled Next.js RSC deserialization in Cal.com (CVSS 10.0)
Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request handling deserializes a...
CVE-2026-12877: unauthenticated SQL injection in Project Management and Issue Tracking plugin for WordPress (CVSS 9.1)
The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it in a SQL query, allowing unauthenticated attackers...
CVE-2026-56163: missing authentication for critical function in Azure Kubernetes Service (CVSS 10.0)
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network....
CVE-2026-56191: improper authentication enabling tampering in Microsoft Exchange Online (CVSS 10.0)
Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network....
CVE-2026-62825: improper authentication in Azure Key Vault (CVSS 10.0)
Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network....
CVE-2026-15981: authentication bypass via loose openssl_verify check in SAML SSO Login plugin (CVSS 9.8)
The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is due to the mo_saml_validate_signature() function pe...
CVE-2026-57784: unauthenticated cross site request forgery (csrf) in Ninja Forms File Uploads Extension (CVSS 9.6)
Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions....
CVE-2026-59514: unauthenticated sql injection in Buddyboss Platform (CVSS 9.3)
Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions....
CVE-2026-59525: unauthenticated sql injection in Participants Database (CVSS 9.3)
Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions....
CVE-2026-59526: unauthenticated sql injection in MapSVG (CVSS 9.3)
Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions....
CVE-2026-59540: unauthenticated privilege escalation in SMS Alert Order Notifications (CVSS 9.8)
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions....
CVE-2026-59544: unauthenticated php object injection in Thrive Quiz Builder (CVSS 9.8)
Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions....
CVE-2026-59555: Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.
Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions....
CVE-2026-60366: unauthenticated compromise of Oracle Platform Security for Java (CVSS 10)
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0....
CVE-2026-60367: unauthenticated compromise of Oracle Platform Security for Java (CVSS 9.8)
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0....
CVE-2026-60369: low privileged compromise of Oracle Platform Security for Java (CVSS 9.9)
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0....
CVE-2026-60372: unauthenticated compromise of Oracle Platform Security for Java (CVSS 9.8)
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0....
CVE-2026-61948: unauthenticated sql injection in WPDM – Premium Packages (CVSS 9.3)
Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions....
CVE-2026-61949: unauthenticated sql injection in Bookly (CVSS 9.3)
Unauthenticated SQL Injection in Bookly <= 27.7 versions....
CVE-2026-61950: unauthenticated sql injection in TrueBooker (CVSS 9.3)
Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions....
CVE-2026-61951: unauthenticated privilege escalation in TrueBooker (CVSS 9.8)
Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions....
CVE-2026-6516: unauthenticated RCE via agent API in ManageEngine ADAudit Plus (CVSS 10.0)
Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API....
CVE-2026-65471: unauthenticated cross site request forgery (csrf) in Avada Core (CVSS 9.6)
Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions....
CVE-2026-16232: Check Point SmartConsole Improper Authentication Vulnerability
Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with ful...
CVE-2026-61145: unauthenticated takeover in Oracle Commerce Guided Search (CVSS 9.8)
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is ...
CVE-2026-61154: unauthenticated compromise of Oracle Commerce Guided Search Platform Services (CVSS 9.8)
Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability...
CVE-2026-61155: unauthenticated compromise of Oracle Commerce Guided Search Platform Services (CVSS 9.1)
Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability...
CVE-2026-61161: unauthenticated takeover via Endeca Application Controller in Oracle Commerce (CVSS 9.8)
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected ...
CVE-2026-61167: unauthenticated compromise of Oracle Agile PLM (CVSS 9.8)
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated a...
CVE-2026-61171: unauthenticated compromise of Oracle Agile PLM (CVSS 9.1)
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated a...
CVE-2026-61174: unauthenticated compromise of Oracle Product Lifecycle Analytics (CVSS 9)
Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerabi...
CVE-2026-61175: unauthenticated compromise of Oracle Product Lifecycle Analytics (CVSS 9.3)
Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerabi...
CVE-2026-61178: unauthenticated compromise of Oracle Agile Product Lifecycle Management for Process (CVSS 9.8)
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation). The supported version that is affected is 6.2.4. Easily exploitab...
CVE-2026-61183: unauthenticated compromise of Oracle Agile Product Lifecycle Management for Process (CVSS 9.8)
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Reporting). The supported version that is affected is 6.2.4. Easily exploitable ...
CVE-2026-61184: unauthenticated compromise of Oracle Agile Product Lifecycle Management for Process (CVSS 9.1)
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4. Ea...
CVE-2026-61186: unauthenticated compromise of Oracle Agile Engineering Data Management (CVSS 9.4)
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Easily exploitable vulnerability a...
CVE-2026-61196: unauthenticated compromise of Oracle Identity Manager (CVSS 9.8)
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vu...
CVE-2026-61197: unauthenticated compromise of Oracle Identity Manager (CVSS 9.1)
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vu...
CVE-2026-61201: unauthenticated compromise of PeopleSoft Enterprise CRM Common Objects (CVSS 9)
Vulnerability in the PeopleSoft Enterprise CRM Common Objects product of Oracle PeopleSoft (component: Common Objects). The supported version that is affected is 9.2.23. Difficult to exploit vulnera...
CVE-2026-61203: unauthenticated compromise of PeopleSoft Enterprise FIN Expenses (CVSS 9.4)
Vulnerability in the PeopleSoft Enterprise FIN Expenses product of Oracle PeopleSoft (component: Expenses). The supported version that is affected is 9.2. Easily exploitable vulnerability allows una...
CVE-2026-61204: low privileged compromise of PeopleSoft Enterprise FIN Program Management (CVSS 9)
Vulnerability in the PeopleSoft Enterprise FIN Program Management product of Oracle PeopleSoft (component: Primavera Integration). The supported version that is affected is 9.2. Easily exploitable v...
CVE-2026-61207: unauthenticated compromise of PeopleSoft Enterprise SCM eProcurement (CVSS 9.3)
Vulnerability in the PeopleSoft Enterprise SCM eProcurement product of Oracle PeopleSoft (component: Manage Requisition Status). The supported version that is affected is 9.2. Easily exploitable vul...
CVE-2026-61209: low privileged compromise of PeopleSoft In-Memory Project Discovery (CVSS 9.9)
Vulnerability in the PeopleSoft In-Memory Project Discovery product of Oracle PeopleSoft (component: Project Discovery). The supported version that is affected is 9.2. Easily exploitable vulnerabili...
CVE-2026-61223: unauthenticated compromise of Oracle Communications Converged Application Server (CVSS 9)
Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Security). Supported versions that are affected are 8.2 and 8.3. Difficult to exp...
CVE-2026-61233: unauthenticated compromise of PeopleSoft Enterprise FIN Common Objects Brazil (CVSS 9.8)
Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Integration). The supported version that is affected is 9.1. Easily exploitable vulnerab...
CVE-2026-61235: high privileged compromise of PeopleSoft Enterprise HCM Global Payroll Switzerland (CVSS 9.1)
Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Switzerland product of Oracle PeopleSoft (component: Global Payroll for Switzerland). The supported version that is affected is 9.2. Eas...
CVE-2026-61237: unauthenticated compromise of PeopleSoft Enterprise FIN Common Objects Argentina (CVSS 9.9)
Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Integration). The supported version that is affected is 9.1. Easily exploitable vulne...
CVE-2026-61238: unauthenticated compromise of PeopleSoft Enterprise FIN Common Objects Argentina (CVSS 9.1)
Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eProcurement). The supported version that is affected is 9.1. Easily exploitable vuln...
CVE-2026-61239: unauthenticated compromise of PeopleSoft Enterprise FIN Common Objects Argentina (CVSS 9.9)
Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eProcurement). The supported version that is affected is 9.1. Easily exploitable vuln...
CVE-2026-61242: low privileged compromise of PeopleSoft Enterprise FIN Common Objects Argentina (CVSS 9.9)
Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Staffing). The supported version that is affected is 9.1. Easily exploitable vulnerab...
CVE-2026-61244: unauthenticated compromise of PeopleSoft Enterprise FIN Manufacturing Argentina (CVSS 9.1)
Vulnerability in the PeopleSoft Enterprise FIN Manufacturing Argentina product of Oracle PeopleSoft (component: Manufacturing). The supported version that is affected is 9.1. Easily exploitable vuln...
CVE-2026-61245: unauthenticated compromise of PeopleSoft Enterprise FIN Manufacturing Brazil (CVSS 9.8)
Vulnerability in the PeopleSoft Enterprise FIN Manufacturing Brazil product of Oracle PeopleSoft (component: Integration). The supported version that is affected is 9.1. Easily exploitable vulnerabi...
CVE-2026-62546: high privileged compromise of Oracle Applications Framework (CVSS 9.1)
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported versions that are affected are 12.2.8-12.2.15. Easily exploitable vulnerabi...
CVE-2026-62549: low privileged compromise of Oracle HRMS (UK) (CVSS 9.6)
Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low ...
CVE-2016-20096: unauthenticated SQL injection in Linknat VOS3000 and VOS2009 login endpoint (CVSS 9.8)
Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands by manipulating the name param...
CVE-2026-13439: unauthenticated privilege escalation via session id as reset token in Easy Form Builder (CVSS 9.8)
The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, and including, 4.0.11 This is due to the password re...
CVE-2026-62415: Unauthenticated Upload in Joomla Membership Pro
The Joomla extension Membership Pro prior version 4.6.2 did by default allow unauthenticated users to upload media assets....
CVE-2026-13147: unauthenticated SSRF in Kirki plugin for WordPress (CVSS 9.1)
The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowing unauthenticated attackers to make the site issue HTTP requests to arbitrary h...
CVE-2026-16242: unauthenticated agent access via misconfigured Konnectivity proxy-server
A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication...
CVE-2026-63766: unauthenticated OS command injection in GPT-SoVITS webui.py (CVSS 9.8)
GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where ASR, slice, denoise, and uvr5 functions interpolate unsanitized Gradio textbox values directly into sh...
CVE-2026-63767: unauthenticated pickle deserialization via ZMQ socket in ktransformers (CVSS 9.8)
ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that allows remote attackers to execute arbitrary commands by sending crafted pic...
CVE-2026-47865: authentication bypass granting Avi Control plane access in VMware Avi Load Balancer (CVSS 9.8)
VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism. A...
CVE-2026-13446: hard-coded credentials used for authentication and encryption in IBM Langflow OSS (CVSS 9.8)
IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external com...
CVE-2026-9103: unauthenticated superuser token issuance via auto_login in IBM Langflow OSS (CVSS 9.8)
IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The endpoint issues long-lived ...
CVE-2023-49899: unauthenticated command execution in X-Rite MA-T6
An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the origin of a communication channel....
CVE-2023-49900: unauthenticated RCE in X-Rite MA-T6 SetParameter command
An unauthenticated remote attacker is able to perform remote code execution due to incorrectly sanitized user input in the SetParameter command....
CVE-2026-12492: authentication bypass without OTP validation in OTP Login for WooCommerce (CVSS 9.8)
The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actually validated before authenticating a user based on a supplied identifier, allo...
CVE-2026-14890: unauthenticated RCE via ZeroMQ PULL socket in SGLang
SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that does not contain authentication or deserialization safeguards, allowing an attack...
CVE-2026-15013: authentication bypass via SAML signature algorithm confusion in SAML SSO Login plugin (CVSS 9.8)
The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all versions up to, and including, 5.4.3. The vulnerability ex...
CVE-2026-22752: Authentication Bypass in Spring Authorization Server
Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Server: from 7.0.0 through 7.0.4, from 1.5.0 through 1....
CVE-2026-63087: unauthenticated PluginAuthToken acquisition in Grafana OnCall (CVSS 9.8)
Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a valid PluginAuthToken by sending a POST request to the internal plugin install ...
CVE-2023-4346: 2023 Vulnerability Now Actively Exploited (KNX Association)
KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that could allow an attacker to purge all devices without addition...
CVE-2026-11563: arbitrary file deletion by low-privileged users in Word Count and Social Shares plugin (CVSS 9.6)
The Word Count and Social Shares WordPress plugin through 1.0 does not validate a user-supplied file path before deletion, nor does it have proper authorization or CSRF checks, allowing any authentica...
CVE-2026-48325: Missing Authentication in Adobe ColdFusion
ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does...
CVE-2026-55040: weak authentication in Microsoft Office SharePoint (CVSS 9.1)
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network....
CVE-2026-56451: JWT algorithm confusion enabling authentication bypass in Siemens Opcenter X (CVSS 10.0)
A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header. This could allow an...
CVE-2026-57898: Unauthenticated Arbitrary File Write in Eclipse BaSyx Java Server SDK
In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB backend are vulnerable to an unauthenticated arbitrary file write through the AAS thum...
CVE-2026-59801: unauthenticated provider management API access in 9Router (CVSS 9.8)
9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to interact with provider management API endpoints by sending requests without any credenti...
CVE-2026-62422: authentication bypass in JetBrains YouTrack (CVSS 10.0)
In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access w...
CVE-2026-15511: OS command injection via filename in Comfast CF-WR631AX FastCGI backend (CVSS 9.8)
A vulnerability was determined in Comfast CF-WR631AX V3 up to 2.7.0.8. Affected by this vulnerability is the function system_wl_upload_pic_file of the file /usr/bin/webmgnt of the component FastCGI Ba...
CVE-2026-4769: undocumented unauthenticated diagnostic capability during boot in WAGO System I/O Field (CVSS 9.8)
Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startup sequence. This functionality is not formally documented and becomes accessible...
CVE-2026-60121: unauthenticated OS command injection via ping.php in Vitec Flamingo (CVSS 9.8)
Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers to execute arbitrary commands by exploiting a doub...
CVE-2026-61498: unauthenticated root command injection via gen_graphs.php in Vitec Flamingo (CVSS 9.8)
Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers to execute arbitrary command...
CVE-2026-20744: unauthenticated charging station websocket endpoint enabling privilege escalation (CVSS 9.8)
The charging station websocket endpoint accepts connections without proper authentication, which could lead to privilege escalation....
CVE-2026-12761: authentication bypass via unverified email in miniOrange Social Login plugin (CVSS 9.8)
The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass leading to account takeover in versions up to and including 7....
CVE-2026-14894: unauthenticated arbitrary file upload via submit_form in Super Forms plugin (CVSS 9.8)
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the submit_form function. This is due to missin...
CVE-2026-40008: unsafe reflection in Apache IoTDB pipe processor (CVSS 9.8)
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache IoTDB. The pipe processor reads a fully qualified Java class name and instantiates it using C...
CVE-2026-57807: authentication Bypass Using an Alternate Path or Channel in miniOrange Security Software Pvt Ltd. O
Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. OAuth Single Sign On - SSO (OAuth Client) allows Password Recovery Exploitation. This i...
CVE-2026-58122: Authentication Bypass in nesquena hermes-webui
Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to circumvent local-origin IP restrictions on onboarding endpoints by supplyin...
CVE-2026-58123: unauthenticated RCE via embedded terminal API in Hermes WebUI (CVSS 9.8)
Hermes WebUI before 0.51.788 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by accessing the embedded terminal API end...
CVE-2026-14245: authentication bypass without OTP verification in miniOrange OTP Login plugin (CVSS 9.8)
The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to, and including,...
CVE-2026-58480: unauthenticated file upload via double extension in Blocksy Companion Pro (CVSS 9.8)
Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upload executable files by bypassing extension validat...
CVE-2026-59705: unauthenticated access to arbitrary user memories in mem0 openmemory API (CVSS 9.8)
mem0's openmemory/api component contains an unauthenticated access vulnerability that allows unauthenticated attackers to read, write, and delete arbitrary user memories by accessing API routers regis...
CVE-2026-9695: improper authentication granting privileged server access in DELMIA Apriso (CVSS 9.8)
An Improper Authentication vulnerability affecting DELMIA Apriso from Release 2020 through Release 2026 could allow an attacker to gain privileged access to the server....
CVE-2026-13019: missing authentication for critical function in Esri Portal for ArcGIS (CVSS 9.8)
Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access ...
CVE-2026-53481: unauthenticated path traversal in Dell PowerProtect Data Domain (CVSS 9.8)
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 throu...
CVE-2026-53483: improper authentication enabling full system takeover in Dell PowerProtect Data Domain (CVSS 9.8)
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 throu...
CVE-2026-5268: SFTP Authentication Bypass in CIENA Network Platforms
An authentication bypass vulnerability exists in the default SFTP server component utilized across the Ciena products listed. This vulnerability allows a remote, unauthenticated attacker to bypass sec...
CVE-2026-9181: unauthenticated directory traversal in Esri ArcGIS Server (CVSS 9.8)
ArcGIS Server contains a directory traversal vulnerability. An unauthenticated attacker could exploit this issue by sending crafted path parameters. Successful exploitation could allow access to sen...
CVE-2026-13768: exposed privileged iothubowner key in Gardyn devices (CVSS 10.0)
Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function which returns connection information for all Gardyn Hom...
CVE-2022-50973: unauthenticated arbitrary file upload in Yonyou KSOA ImageUpload servlet (CVSS 9.8)
Yonyou KSOA 9.0 contains an unauthenticated arbitrary file upload vulnerability in the com.sksoft.bill.ImageUpload servlet that allows unauthenticated attackers to upload arbitrary files by submitting...
CVE-2026-4767: missing authentication for critical function in TR7 WAF-ASP (CVSS 9.8)
Missing authentication for critical function vulnerability in TR7 Cyber Defense Inc. WAF-ASP allows Authentication Abuse. This issue affects WAF-ASP: from v1.0.324.900 before v1.4.0.117....
CVE-2026-50747: authenticated SQL injection enabling privilege escalation in UniFi Talk (CVSS 9.9)
A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi Talk Application to escalate privileges on the host...
CVE-2026-57621: unauthenticated php object injection in Booktics (CVSS 9.8)
Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions....
CVE-2026-57623: unauthenticated arbitrary code execution in W3 Total Cache (CVSS 9)
Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions....
CVE-2026-57624: Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions.
Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions....
CVE-2026-57625: unauthenticated cross site scripting (xss) in Admin and Site Enhancements (ASE) Pro (CVSS 9.6)
Unauthenticated Cross Site Scripting (XSS) in Admin and Site Enhancements (ASE) Pro <= 8.8.5 versions....
CVE-2026-57677: unauthenticated php object injection in Novalnet Payment Gateway for WooCommerce (CVSS 9.8)
Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions....
CVE-2026-57679: unauthenticated sql injection in GeekyBot (CVSS 9.3)
Unauthenticated SQL Injection in GeekyBot <= 1.2.5 versions....
CVE-2026-57683: unauthenticated sql injection in WP Fast Total Search (CVSS 9.3)
Unauthenticated SQL Injection in WP Fast Total Search <= 1.80.280 versions....
CVE-2026-58455: unauthenticated OS command injection via composePath in Dockwatch (CVSS 9.8)
Dockwatch through 0.6.567 contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands by exploiting a missing exit() after an authen...
CVE-2026-11387: account takeover via unvalidated identity in SMS Alert plugin for WordPress (CVSS 9.8)
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and incl...
CVE-2026-24270: authentication bypass in NVIDIA AIStore framework (CVSS 9.8)
NVIDIA AIStore framework contains a vulnerability where an attacker could bypass authentication. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, i...
CVE-2026-56413: unauthenticated root command injection in StoneFly Storage Concentrator ms_service.pl (CVSS 10.0)
Storage Concentrator (SC & SCVM) contains a command injection vulnerability in the ms_service.pl service, which listens on TCP port 9000 by default and accepts custom network packets to perform device...
CVE-2026-56415: unauthenticated root command injection via debug.pl in StoneFly Storage Concentrator (CVSS 10.0)
Storage Concentrator (SC & SCVM) contains a command injection vulnerability within the debug.pl script that is reachable without authentication. A remote attacker can submit a specially crafted HTTP r...
CVE-2026-57517: unauthenticated blind SQL injection leading to RCE in Control Web Panel (CVSS 9.8)
Control Web Panel before 0.9.8.1225 contains a blind SQL injection vulnerability that allows unauthenticated remote attackers to execute arbitrary SQL queries by submitting unsanitized input through t...
CVE-2026-58126: unauthenticated .NET Remoting file read/write and DLL hijacking in PACSgear PACS Scan (CVSS 9.8)
PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote attackers to read and write arbitrary files by exploiting an exposed .NET Remoting TCP servi...
CVE-2026-58127: unauthenticated .NET Remoting file read/write in PACSgear MediaWriter (CVSS 9.8)
PACSgear MediaWriter 5.2.1 exposes a .NET Remoting TCP service on port 9000 via PacsgearMediaServerEngine.dll, registered with ObjectURIs RemoteObj and UIRemoteObj, without any authentication requirem...
CVE-2026-58449: unauthenticated RCE via /reindex function resolver in txtai (CVSS 9.8)
txtai through 9.10.0, fixed in commit 11b32da, exposes an API /reindex endpoint whose function body parameter is resolved through txtai.util.Resolver, which performs __import__ and getattr on the call...
CVE-2026-58457: unauthenticated OS command injection via smacfilter_conf in Aitemi M300 repeater (CVSS 9.8)
Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) contains an unauthenticated OS command injection vulnerability that allows network-adjacent attackers to execute arbitrary shell commands by i...
CVE-2026-14162: unauthenticated API documentation exposure in Advantech Hospital Queuing Management (CVSS 9.8)
Hospital Queuing Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access a specific URL to obtain API documentation....
CVE-2026-58138: unauthenticated RCE via unsandboxed GraalVM evaluators in Orkes Conductor (CVSS 9.8)
Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow defini...
CVE-2026-7873: authenticated OS command execution and file disclosure in IBM Langflow OSS (CVSS 9.9)
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary OS commands and read sensitive files including credentials, enabling complete system compromise and lateral mo...
CVE-2026-9711: unauthenticated SQL injection via search parameter in EventON plugin for WordPress (CVSS 9.8)
The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress (full) is vulnerable to SQL Injection via the WordPress 'search' parameter in versions up to, and including, 5.0.11 due to in...
CVE-2026-56782: authentication bypass in /api/dump and /api/restore endpoints in Gorse (CVSS 9.8)
Gorse before 0.5.10 contains an authentication bypass vulnerability in the /api/dump and /api/restore endpoints that allows unauthenticated attackers to access protected functionality when admin_api_k...
CVE-2025-71327: authentication bypass in FlowiseAI Flowise registration endpoint
Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that allows unauthenticated attackers to create user accounts. Remote attackers can exploit...
CVE-2025-71338: unauthenticated path traversal to RCE in Flowise document store loader (CVSS 10.0)
Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint that allows unauthenticated attackers to write arbitrary files to the filesystem. Attackers can ex...
CVE-2026-40702: Unauthenticated WebSocket Charging Station Impersonation
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitiv...
CVE-2026-54820: unauthenticated sql injection in JetBooking (CVSS 9.3)
Unauthenticated SQL Injection in JetBooking <= 4.0.4.1 versions....
CVE-2026-54825: unauthenticated sql injection in wpDataTables (CVSS 9.3)
Unauthenticated SQL Injection in wpDataTables <= 7.4 versions....
CVE-2026-54827: unauthenticated sql injection in Real Estate 7 (CVSS 9.3)
Unauthenticated SQL Injection in Real Estate 7 <= 3.5.9 versions....
CVE-2026-54831: unauthenticated sql injection in GeoDirectory (CVSS 9.3)
Unauthenticated SQL Injection in GeoDirectory <= 2.8.162 versions....
CVE-2026-56028: unauthenticated privilege escalation in Easy Elements for Elementor – Addons & Website Templates
Unauthenticated Privilege Escalation in Easy Elements for Elementor – Addons & Website Templates <= 1.4.9 versions....
CVE-2026-56030: unauthenticated privilege escalation in Paytium (CVSS 9.8)
Unauthenticated Privilege Escalation in Paytium <= 5.0.2 versions....
CVE-2026-56033: unauthenticated privilege escalation in Dokan Pro (CVSS 9.8)
Unauthenticated Privilege Escalation in Dokan Pro <= 5.0.4 versions....
CVE-2026-56034: unauthenticated sql injection in Library Management System (CVSS 9.3)
Unauthenticated SQL Injection in Library Management System <= 3.5.7 versions....
CVE-2026-56036: unauthenticated sql injection in 워드프레스 결제 심플페이 (CVSS 9.3)
Unauthenticated SQL Injection in 워드프레스 결제 심플페이 <= 5.5.6 versions....
CVE-2026-56062: unauthenticated sql injection in Quotes llama (CVSS 9.3)
Unauthenticated SQL Injection in Quotes llama <= 3.1.5 versions....
CVE-2026-56067: unauthenticated sql injection in JetSmartFilters (CVSS 9.3)
Unauthenticated SQL Injection in JetSmartFilters <= 3.8.3 versions....
CVE-2026-56068: unauthenticated sql injection in JetEngine (CVSS 9.3)
Unauthenticated SQL Injection in JetEngine <= 3.8.10.2 versions....
CVE-2026-56070: unauthenticated sql injection in Advance Product Search (CVSS 9.3)
Unauthenticated SQL Injection in Advance Product Search <= 1.4.4 versions....
CVE-2026-57878: unauthenticated stack overflow in thttpd on GeoVision GV-LPC2011/2211 (CVSS 9.8)
An unauthenticated stack-based buffer overflow vulnerability exists in thttpd in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when...
CVE-2026-57879: unauthenticated stack overflow in ssvr RTSP auth on GeoVision GV-LPC2011/2211 (CVSS 9.8)
An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when p...
CVE-2026-57880: unauthenticated stack overflow parsing RTSP Digest fields on GeoVision GV-LPC2011/2211 (CVSS 9.8)
An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when p...
CVE-2026-57881: unauthenticated stack overflow in vlsvr remote login on GeoVision GV-LPC2011/2211 (CVSS 9.8)
An unauthenticated stack-based buffer overflow vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient length validation whe...
CVE-2026-54843: unauthenticated sql injection in MDTF (CVSS 9.3)
Unauthenticated SQL Injection in MDTF <= 1.3.7 versions....
CVE-2026-54849: unauthenticated sql injection in Premmerce Wishlist for WooCommerce (CVSS 9.3)
Unauthenticated SQL Injection in Premmerce Wishlist for WooCommerce <= 1.1.11 versions....
CVE-2026-12417: authentication bypass via weak password reset validation in SignUp & SignIn plugin (CVSS 9.8)
The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation leading to Account Takeover in versions up to, and including, 1.0.0. This is due to t...
CVE-2026-12485: unauthenticated stack overflow in DVRSearch UDP service on GeoVision GV-I/O Box 4E (CVSS 10.0)
GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service running by default on the IOBox listening for UDP mes...
CVE-2026-11374: SSO Token Prediction in ManageEngine ADSelfService Plus
In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, le...
CVE-2026-10561: authentication bypass and Python sandbox escape in IBM Langflow OSS (CVSS 10.0)
IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arb...
CVE-2019-25763: authentication bypass via social login form in Ultimate Addons for Beaver Builder (CVSS 9.8)
WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability that allows attackers to gain unauthorized access by exploiting the social media login form functio...
CVE-2026-11551: unauthenticated password change enabling account takeover in Branda plugin (CVSS 9.8)
The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.29. This is due to the plugin not properly validating a user's iden...
CVE-2026-56073: OTP Verification Authentication Bypass in Capgo
Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP verification that allows attackers to bypass email verification by modifying server responses. Attackers can intercept OTP...
CVE-2026-45480: improper authentication allowing privilege elevation in Azure Active Directory (CVSS 10.0)
Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network....
CVE-2026-54130: missing authentication for critical function in M365 Copilot (CVSS 9.8)
Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network....
CVE-2026-7515: unauthenticated local file inclusion via doc_style in BetterDocs Pro (CVSS 9.8)
The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.8.0 via the `doc_style` parameter. This makes it possible for unauthenticated attacker...
CVE-2026-54103: unauthenticated password change via /update-profile endpoint in GAO EPDS and CBCA EDS (CVSS 9.8)
The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) does not authenticate passwor...
CVE-2026-54390: unauthenticated server-side template injection in JTL Shop (CVSS 9.8)
JTL Shop versions 5.2.0 through 5.7.1 contains a server-side template injection vulnerability that allows unauthenticated attackers to inject malicious template syntax due to unsanitized user-supplied...
CVE-2026-54419: multiple unauthenticated SQL injections in PIAF-HMS hotel management system (CVSS 9.8)
claudiopizzillo PIAF-HMS (PBX-In-A-Flash Hotel Management System; no released versions, latest commit 389d2633441b65ced1c104212cd62be2bfca21e5) contains multiple unauthenticated SQL injection vulnerab...
CVE-2026-55740: unauthenticated SQL injection via busid in Nur-Alam39 bus-ticket (CVSS 9.8)
Nur-Alam39 bus-ticket (no released versions; latest commit 459cabdbeb99c00225b26e46e3c2c30ae1de7bad) contains an unauthenticated SQL injection vulnerability in bus_info.php. The busid parameter receiv...
CVE-2026-8024: unauthenticated deserialization of untrusted data in ibaPDA and ibaDatCoordinator (CVSS 9.8)
A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA or ibaDatCoordinator to gain full access to the affected systems....
CVE-2025-59554: Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions.
Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions....
CVE-2025-69111: unauthenticated php object injection in Reisen (CVSS 9.8)
Unauthenticated PHP Object Injection in Reisen <= 1.4.1 versions....
CVE-2025-69127: unauthenticated php object injection in Plumbing (CVSS 9.8)
Unauthenticated PHP Object Injection in Plumbing <= 1.6 versions....
CVE-2026-20181: Authenticated Command Execution in Cisco ISE
A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerabi...
CVE-2026-49108: Unauthenticated PHP Object Injection in Moderno < 1.43 versions.
Unauthenticated PHP Object Injection in Moderno < 1.43 versions....
CVE-2026-53805: unauthenticated pickle deserialization RCE in NVIDIA GEN3C inference API (CVSS 9.8)
NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inference API server where the /request-inference and /seed-model endpoints deseria...
CVE-2026-54807: unauthenticated privilege escalation in Registration Form for WooCommerce (CVSS 9.8)
Unauthenticated Privilege Escalation in Registration Form for WooCommerce <= 1.0.9 versions....
Blocking the Device Code Flow in Microsoft Entra ID with Conditional Access
Device Code Phishing abuses a flow that most organizations don't even need. We show how to disable or restrict the Device Code Flow in Entra ID with Conditional Access — step by step, with pitfalls and validation.
Device Code Phishing: what it is and how the attack on Microsoft Entra ID works
An attacker doesn't need your password — they just need you to enter a code they supplied. See how Device Code Phishing abuses the OAuth2 Device Code Flow in Microsoft Entra ID and why it can bypass MFA.
Infostealers and session theft: why MFA isn't enough and how to protect yourself
In 2025, infostealers infected 11.1 million machines and produced 3.3 billion stolen credentials. By stealing cookies and session tokens, they bypass even MFA. We explain the mechanism and show how to defend.
CVE-2026-39574: unauthenticated sql injection in InPost Gallery (CVSS 9.3)
Unauthenticated SQL Injection in InPost Gallery <= 2.1.4.6 versions....
CVE-2026-52715: unauthenticated sql injection in GEO my WordPress (CVSS 9.3)
Unauthenticated SQL Injection in GEO my WordPress <= 4.5.5 versions....
CVE-2026-45439: unauthenticated sql injection in Realtyna Organic IDX plugin (CVSS 9.3)
Unauthenticated SQL Injection in Realtyna Organic IDX plugin <= 5.1.0 versions....
CVE-2026-48881: unauthenticated broken access control in TrueBooker (CVSS 9.1)
Unauthenticated Broken Access Control in TrueBooker <= 1.1.9 versions....
CVE-2026-49067: unauthenticated sql injection in Advanced 301 and 302 Redirect (CVSS 9.3)
Unauthenticated SQL Injection in Advanced 301 and 302 Redirect <= 1.6.9 versions....
CVE-2026-49085: unauthenticated php object injection in WP Insightly (CVSS 9.8)
Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions....
CVE-2026-49104: unauthenticated php object injection in Integration for Keap/infusionsoft (CVSS 9.8)
Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.2.1 versions....
CVE-2026-49105: unauthenticated php object injection in WP Zendesk (CVSS 9.8)
Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions....
CVE-2026-49106: unauthenticated php object injection in Integration for Contact Form 7 and Constant Contact (CVSS 9.8)
Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Constant Contact <= 1.1.6 versions....
CVE-2026-49109: unauthenticated php object injection in Integration for Salesforce (CVSS 9.8)
Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.4.3 versions....
CVE-2026-49763: unauthenticated php object injection in Integration for Contact Form 7 HubSpot (CVSS 9.8)
Unauthenticated PHP Object Injection in Integration for Contact Form 7 HubSpot <= 1.3.7 versions....
CVE-2026-49764: unauthenticated broken authentication in RegistrationMagic (CVSS 9.8)
Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.8.6 versions....
CVE-2026-49765: unauthenticated php object injection in Integration for Mailchimp (CVSS 9.8)
Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.8 versions....
CVE-2026-49768: unauthenticated php object injection in Happyforms (CVSS 9.8)
Unauthenticated PHP Object Injection in Happyforms <= 1.26.13 versions....
CVE-2026-49769: unauthenticated php object injection in wpForo Forum (CVSS 9.8)
Unauthenticated PHP Object Injection in wpForo Forum <= 3.1.0 versions....
CVE-2026-49770: unauthenticated php object injection in WP Travel Engine (CVSS 9.8)
Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions....
CVE-2026-49776: unauthenticated sql injection in GPTranslate – Multilingual AI Translation for WordPress
Unauthenticated SQL Injection in GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites <= 2.32.6 versions....
CVE-2026-49781: unauthenticated php object injection in OttoKit (CVSS 9.8)
Unauthenticated PHP Object Injection in OttoKit <= 1.1.27 versions....
CVE-2026-52693: unauthenticated sql injection in eCommerce Product Catalog (CVSS 9.3)
Unauthenticated SQL Injection in eCommerce Product Catalog <= 3.5.5 versions....
CVE-2026-52703: unauthenticated path traversal in FastDup (CVSS 9.6)
Unauthenticated Path Traversal in FastDup <= 2.7.2 versions....
CVE-2026-8935: unauthenticated admin account creation in WP MAPS PRO plugin for WordPress (CVSS 9.8)
The WP MAPS PRO WordPress plugin before 6.1.1 registers an unauthenticated AJAX action which, given a valid nonce that is publicly emitted on any frontend page enqueuing its map script, unconditionall...
CVE-2026-9691: unauthenticated php object injection in Integration for ActiveCampaign (CVSS 9.8)
Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions....
CVE-2026-9862: OS command injection in boks_autoregisterd in Fortra Core Privileged Access Manager (CVSS 9.8)
Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to ca...
CVE-2026-48611: account hijacking via improper OAuth authentication checks (CVSS 9.8)
Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations....
CVE-2026-50083: Hardcoded OAuth Credential in Aqara IAM/SSO Gateway
The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of "CWE-798: Use of Hard-coded Credentials." This issue has an estimated CVSS of CVSS:3....
CVE-2026-50086: unauthenticated AES oracle against platform signing key in Aqara IAM/SSO gateway (CVSS 10.0)
The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing key without authentication. This is an instance of "CWE-306: Missing Authenticatio...
CVE-2026-53787: unauthenticated arbitrary file upload in Amasty Order Attributes for Magento 2 (CVSS 9.8)
Amasty Order Attributes for Magento 2 before version 4.0.0 contains an unauthenticated arbitrary file upload vulnerability that allows unauthenticated attackers to write arbitrary files to the store's...
CVE-2026-6853: authentication bypass via unrestricted authentication attempts in Pause+ Mobile App (CVSS 9.8)
Improper restriction of excessive authentication attempts vulnerability in Başbelen Group Food Cafe Businesses Industry and Trade Ltd. Co. Pause+ Mobile App allows Authentication Bypass. This issue a...
CVE-2026-35273: unauthenticated compromise of PeopleSoft Enterprise PeopleTools (CVSS 9.8)
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploita...
CVE-2026-41005: SAML Signature Bypass in Cloud Foundry UAA
Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML signatures from the Identity Provider (authenticity) in two SAML flows: the OAuth...
CVE-2025-6254: unauthenticated admin registration in Doctreat Core plugin for WordPress (CVSS 9.8)
The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8. This is due to the doctreat_process_registration() function not properly restr...
CVE-2026-20253: unauthenticated arbitrary file write via PostgreSQL sidecar in Splunk Enterprise (CVSS 9.8)
In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.3 and 10.2.2510.14, an unauthenticated user could create or truncate arbitrary files through a...
CVE-2009-10007: session fixation in Perl Catalyst::Plugin::Authentication (CVSS 9.1)
Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks. Catalyst::Plugin::Authentication does not automatically change the session id after auth...
CVE-2017-20251: unauthenticated PHP code injection via REST API in WordPress Insert PHP plugin (CVSS 9.8)
WordPress Insert PHP plugin versions before 3.3.1 contain a PHP code injection vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by injecting malicious shortcodes throu...
CVE-2026-10520: unauthenticated root-level OS command injection in Ivanti Sentry (CVSS 10.0)
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution...
CVE-2026-10523: authentication bypass allowing admin account creation in Ivanti Sentry (CVSS 9.9)
An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts ...
CVE-2026-25089: unauthenticated OS command injection in Fortinet FortiSandbox (CVSS 9.8)
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox ...
CVE-2026-25555: Authentication bypass in openbullet OpenBullet2
OpenBullet2 through version 0.3.2 contains an authentication bypass vulnerability in the API key authentication middleware that allows unauthenticated attackers to gain admin access by supplying an em...
CVE-2026-41448: Authentication bypass in AdguardTeam AdGuard Home
AdGuard Home, when started with the --glinet flag, contains an authentication bypass vulnerability that allows unauthenticated attackers to gain full admin access by supplying a path traversal sequenc...
CVE-2025-1740: Improper restriction of authentication attempts in Akinsoft MyRezzta
Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft MyRezzta allows Authentication Bypass, Password Recovery Exploitation, Brute Force. This issue affects MyRezzta: fr...
CVE-2025-71318: Missing Authentication in Riello NetMan 204
NetMan 204 fails to enforce authentication on its administrative pages and command endpoints. A remote, unauthenticated attacker can directly request administrative pages (such as administration.html,...
CVE-2026-10580: Authentication Bypass in Hippoo Mobile App for WooCommerce (plugin)
The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to and including 1.9.4. This is due to a ...
CVE-2026-48567: Authentication Bypass in Microsoft Azure HorizonDB
Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network....
CVE-2026-6274: Authentication Bypass in DTS Electronics Redline WR3200
Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Electronics Industry and Trade Ltd. Co. Redline WR3200 allows Accessing Functionality No...
CVE-2019-25738: Unauthenticated settings change in WordPress Hybrid Composer (plugin)
WordPress Hybrid Composer 1.4.6 contains an unauthenticated settings change vulnerability that allows unauthenticated attackers to modify WordPress options by exploiting the hc_ajax_save_option action...
CVE-2026-0611: Unauthenticated RCE in Spacelabs Healthcare Sentinel
Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6.0 contain an unauthenticated remote code execution vulnerability through a deprecated .NET Remoting HTTP channel exposed...
CVE-2026-48188: Unauthenticated SQL Injection in OTRS
An improper Input Validation vulnerability in OTRS or ((OTRS)) Community Edition database layer module allows an unauthenticated SQL injection which can lead to an authentication bypass. This issue on...
CVE-2026-7858: Unauthenticated RCE via Deserialization in Dassault Systemes Teamwork Cloud
A Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic Release 2026x and Magic Collaboration Studio from CATIA Magic Release 2022x thro...
CVE-2026-8644: IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing....
CVE-2026-0257: Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection....
CVE-2026-3655: Authentication Bypass in WordPress OTP Login With Phone Number plugin
The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass in versions 1.8.50 through 1.8.60. This is due to the Firebase verification flow in the `l...
CVE-2026-5386: Unauthenticated Password Reset in KMW CCTV Security Cameras
The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset. This flaw allows an attacker to remotely reset the administrator password to a known value without a...
CVE-2026-9051: Authentication Bypass in NI SystemLink Enterprise
There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard application that may allow an unauthenticated remote attacker to bypass authentication controls leading to pri...
CVE-2026-8364: Unauthenticated remote access in Gladinet Triofox
Gladinet Triofox Cloud Server Agent Access Service (GladServerAgentService.exe) listens on TCP port 7878 and processes remote HTTP messages with URL paths starting with /resources, /status, /sysinfo, ...
CVE-2026-8760: Authentication Bypass in WordPress Login with OTP plugin
The Login with OTP plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.6. This is due to an incomplete fix for CVE-2024-11178: the rate-limit/lockout ch...
CVE-2026-33843: Authentication bypass in Microsoft Azure Active Directory B2C
Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network....
CVE-2026-47280: Improper authentication in Microsoft Azure Resource Manager
Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network....
CVE-2026-9642: Unauthenticated Database Access in WellinTech DIAView (CVE-2025-62582 Bypass)
Incomplete fix for CVE-2025-62582 - an unauthenticated remote attacker can still access configured databases in a WellinTech DIAView project...
CVE-2026-6279: Unauthenticated RCE in WordPress Avada Builder plugin
The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unauthenticated Remote Code Execution via PHP Function Injection in versions up to and including 3.15.2. This is due to the `wp...
CVE-2026-20223: Critical Authentication Bypass in Cisco Secure Workload
Critical access-validation vulnerability in Cisco Secure Workload internal REST APIs (3.9.x and earlier, 3.10.x < 3.10.8.3, 4.0.x < 4.0.3.17) - unauthenticated remote attacker can obtain Site Admin privileges...
CVE-2026-24207: Authentication bypass in NVIDIA Triton Inference Server
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to code execution, escalation of p...
CVE-2026-8598: Unauthenticated config export port in ZKTeco CCTV Camera
An undocumented configuration export port is accessible on some models of ZKTeco CCTV cameras. This port does not require authentication and exposes critical information about the camera such as ope...
CVE-2026-9141: Authentication bypass in Taiko AG1000-01A SMS Alert Gateway
Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains an authentication bypass vulnerability in the embedded web configuration interface that allows unauthenticated attackers to access interna...
CVE-2026-2586: Authenticated RCE in Eclipse GlassFish Admin Console
An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of a...
CVE-2026-36829: Authentication bypass in Panabit PAP-XM320
An authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 up to and including v7.7. The server validates session cookies using a filesystem existence check based o...
CVE-2026-43633: Unauthenticated Deserialization RCE in HestiaCP
HestiaCP versions 1.9.0 through 1.9.4 contain a deserialization vulnerability in the web terminal component caused by a session format mismatch between PHP and Node.js that allows unauthenticated remo...
CVE-2026-44159: Default Admin Credentials in Tyler Identity Local (TID-L)
Tyler Identity Local (TID-L) uses documented, default administrative credentials. Users are not required to change the credentials before deployment. TID-L has not been distributed since December 2020...
CVE-2026-7301: Unauthenticated RCE in SGLang multimodal runtime
SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when exposed to the interne...
CVE-2026-7302: Unauthenticated path traversal in SGLang
SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by i...
CVE-2026-7304: Unauthenticated RCE in SGLang custom logit processor
SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will ...
CVE-2018-25332: Unauthenticated RCE in GitBucket
GitBucket 4.23.1 contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary commands by exploiting weak secret token generation and insecure file upload...
CVE-2026-5229: Authentication Bypass in WordPress Form Notify plugin
The Form Notify plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.1.10. This is due to the plugin trusting user-controlled cookie data to determine which Wo...
CVE-2026-20182: Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges ...
CVE-2026-41615: Information Disclosure in Microsoft Authenticator
Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a network....
CVE-2026-8181: Authentication bypass in WordPress Burst Statistics (plugin)
Authentication bypass in Burst Statistics WordPress plugin versions 3.4.0 to 3.4.1.1 due to incorrect return-value handling in is_mainwp_authenticated(). Unauthenticated attackers with knowledge of admin username can impersonate that administrator...
CVE-2026-40621: Missing Authentication in ELECOM Wireless LAN Access Points
ELECOM wireless LAN access point devices do not require authentication to access some specific URLs. The affected product may be operated without authentication....
CVE-2025-40949: Unauthenticated RCE in Siemens RUGGEDCOM ROX
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX RX1400 (All versions < V2.17.1), RUGGEDCOM ROX RX15...
CVE-2026-31242: Missing Authentication in mem0 Server (DELETE /memories)
The mem0 v1.0.0 server lacks authentication and authorization controls for its memory reset functionality accessible via the DELETE /memories endpoint. An unauthenticated attacker can send a DELETE re...
CVE-2026-33117: Improper authentication in Azure SDK allows security feature bypass
Improper authentication in Azure SDK allows an unauthorized attacker to bypass a security feature over a network....
CVE-2026-34263: Unauthenticated Code Injection in SAP Commerce Cloud
Due to improper Spring Security configuration, SAP Commerce cloud allows an unauthenticated user to perform malicious configuration upload and code injection, resulting in arbitrary server-side code e...
CVE-2026-41103: Privilege Escalation in Microsoft SSO Plugin for Jira & Confluence
Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unauthorized attacker to elevate privileges over a network...
CVE-2026-44277: Improper Access Control in Fortinet FortiAuthenticator
An improper access control vulnerability in Fortinet FortiAuthenticator versions 8.0.2, 8.0.0, 6.6.0-6.6.8 and 6.5.0-6.5.6 may allow an attacker to execute unauthorized code or commands....
CVE-2026-7415: Unauthenticated MQTT access in Yarbo Yarbo Firmware
The MQTT broker embedded in Yarbo firmware v2.3.9 allows anonymous connections with no ACLs. Any host on the same network can subscribe to sensitive telemetry or publish control commands to the robot...
CVE-2026-5722: Authentication Bypass in WordPress MoreConvert Pro plugin
The MoreConvert Pro plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.9.14. This is due to the guest waitlist verification flow not invalidating or re...
CVE-2026-42796: Unauthenticated RCE in Arelle (/rest/configure)
Arelle before 2.39.10 contains an unauthenticated remote code execution vulnerability in the /rest/configure endpoint - the plugins parameter is forwarded to the plugin manager without authorization, allowing remote code execution...
CVE-2026-42810: Wildcard injection in Apache Polaris (S3 IAM)
Apache Polaris accepts literal * characters in namespace and table names. Those characters are reused unescaped in S3 IAM policies, allowing an attacker to broaden the scope of temporary credentials to other tables...
CVE-2026-7458: Authentication bypass in WordPress User Verification by PickPlugins
The User Verification by PickPlugins plugin for WordPress (versions up to and including 2.0.46) allows unauthenticated attackers to log in as any user with a verified email by submitting an OTP value of "true"...
CVE-2026-7567: Authentication bypass in WordPress Temporary Login plugin
The Temporary Login plugin for WordPress (versions up to and including 1.0.0) contains an authentication bypass in the maybe_login_temporary_user() function. Passing an array instead of a string in the GET parameter lets an attacker log in as an arbitrary user, typically an administrator...
CVE-2018-25316: Authentication bypass in Tenda W308R router
Tenda W308R v2 V5.07.48 contains a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings and redirect user traffic to malicious sites.
CVE-2018-25317: Authentication bypass in Tenda W3002R/A302/W309R routers
Tenda W3002R/A302/W309R wireless routers running V5.07.64_en contain a cookie session weakness allowing unauthenticated attackers to alter DNS servers and redirect user traffic.
CVE-2018-25318: Authentication bypass in Tenda FH303/A300 routers
Tenda FH303/A300 firmware V5.07.68_EN contains a session weakness vulnerability that allows unauthenticated attackers to modify DNS settings and redirect user traffic to malicious sites.
CVE-2026-41940: Authentication bypass in cPanel & WHM login flow
cPanel and WHM versions prior to 11.110.0.97, 11.118.0.63, 11.126.0.54, 11.132.0.29, 11.134.0.20, and 11.136.0.5 contain an authentication bypass vulnerability in the login flow allowing unauthenticated remote attackers to access the control panel.
CVE-2026-41462: Unauthenticated SQL injection in ProjeQtor
ProjeQtor versions 7.0 through 12.4.3 contain an unauthenticated SQL injection vulnerability in the login functionality where the login variable is directly concatenated into a SQL query without parameterization...
CVE-2026-25775: Unauthenticated firmware update in SenseLive X3050
SenseLive X3050's remote management service allows firmware retrieval and update operations without authentication or authorization, enabling full device takeover...
CVE-2026-35503: Client-side authentication bypass in SenseLive X3050
SenseLive X3050's web interface performs authentication entirely on the client side - an attacker reading the login page scripts can obtain administrative access...
CVE-2026-40620: Unauthenticated management service in SenseLive X3050
SenseLive X3050's embedded management service allows full administrative takeover without authentication - any host on the network can modify configuration and operating mode...
CVE-2026-23751: Unauthenticated .NET Remoting access in Kofax Capture / Tungsten Capture
Kofax Capture (now Tungsten Capture) version 6.0.0.0 exposes a deprecated .NET Remoting HTTP channel on port 2424 accessible without authentication, allowing arbitrary file read and write...
CVE-2026-6886: Authentication bypass in Borg SPM 2007
Borg SPM 2007 by BorG Technology Corporation has an Authentication Bypass vulnerability allowing unauthenticated remote attackers to log into the system as any user...
CVE-2026-34275: Unauthenticated takeover of Oracle Advanced Inbound Telephony (E-Business Suite)
Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: Setup and Administration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploi...
CVE-2026-34285: Unauthenticated data tampering in Oracle Identity Manager Connector (Fusion Middleware)
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability a...
CVE-2026-34286: Unauthenticated data tampering in Oracle Identity Manager Connector (Fusion Middleware)
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability a...
CVE-2026-34287: Unauthenticated data tampering in Oracle Identity Manager Connector (Fusion Middleware)
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability a...
CVE-2026-40050: Unauthenticated path traversal in CrowdStrike LogScale
CrowdStrike has released security updates to address a critical unauthenticated path traversal vulnerability (CVE-2026-40050) in LogScale. This vulnerability only requires mitigation by customers that...
CVE-2025-32975: Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability
Quest KACE Systems Management Appliance (SMA) contains an improper authentication vulnerability that could allow attackers to impersonate legitimate users without valid credentials....
What is passwordless authentication? Methods, benefits and implementation
Passwordless authentication eliminates passwords, replacing them with biometrics, hardware keys and magic links. How it works and how to implement it.
CVE-2026-31843: Unauthenticated PHP file overwrite in Laravel pay-uz package
The goodoneuz/pay-uz Laravel package (<= 2.2.24) contains a critical vulnerability in the /payment/api/editable/update endpoint that allows unauthenticated attackers to overwrite existing PHP payment ...
CVE-2026-20147: Authenticated command execution in Cisco ISE
A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vul...
CVE-2026-20180: Authenticated command execution in Cisco Identity Services Engine
A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit...
CVE-2026-20184: SSO impersonation in Cisco Webex Services Control Hub
A vulnerability in the integration of single sign-on (SSO) with Control Hub in Cisco Webex Services could have allowed an unauthenticated, remote attacker to impersonate any user within the service. ...
CVE-2026-20186: Authenticated command execution in Cisco Identity Services Engine
A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit...
CVE-2026-6264: Unauthenticated RCE via JMX port in Talend JobServer
A critical vulnerability in the Talend JobServer and Talend Runtime allows unauthenticated remote code execution via the JMX monitoring port. The attack vector is the JMX monitoring port of the Talend...
Passwordless Authentication: The Future of Secure Login
Passwordless authentication eliminates passwords in favor of biometrics, passkeys, FIDO2 tokens, and magic links. Learn how it works, why it's more secure, and how to implement it.
CVE-2026-0233 and CVE-2026-0234: Critical Vulnerabilities in Palo Alto Networks Cortex XSOAR, XSIAM and ADEM - Immediate Update Required
Two high severity vulnerabilities have been identified in Palo Alto Networks Cortex XSOAR, Cortex XSIAM, and ADEM. CVE-2026-0233 and CVE-2026-0234 could allow an unauthenticated attacker to bypass security mechanisms and execute arbitrary code on affected systems.
CVE-2026-1830: Unauthenticated RCE via REST API in Quick Playground plugin for WordPress
The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.1. This is due to insufficient authorization checks on REST API endpoints tha...
CVE-2026-39912: Authentication token leak via loginWithMailLink in V2Board/Xboard
V2Board 1.6.1 through 1.7.4 and Xboard through 0.1.9 expose authentication tokens in HTTP response bodies of the loginWithMailLink endpoint when the login_with_mail_link_enable feature is active. Unau...
CVE-2026-22679: Unauthenticated RCE via Dubbo debug endpoint in Weaver E-cology
Weaver (Fanwei) E-cology 10.0 versions prior to 20260312 contain an unauthenticated remote code execution vulnerability in the /papi/esearch/data/devops/dubboApi/debug/method endpoint that allows atta...
CVE-2017-20234: Authentication bypass via hardcoded credentials in GarrettCom Magnum switches
GarrettCom Magnum 6K and 10K managed switches contain an authentication bypass vulnerability that allows unauthenticated attackers to gain unauthorized access by exploiting a hardcoded string in the a...
CVE-2017-20235: Authentication bypass in ProSoft Technology ICX35-HWC web UI
ProSoft Technology ICX35-HWC version 1.3 and prior cellular gateways contain an authentication bypass vulnerability in the web user interface that allows unauthenticated attackers to gain access to ad...
CVE-2018-25236: Authentication bypass in Hirschmann HiOS/HiSecOS management
Hirschmann HiOS and HiSecOS products RSP, RSPE, RSPS, RSPL, MSP, EES, EESX, GRS, OS, RED, EAGLE contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauthentica...
CVE-2017-20237: Authentication bypass in Hirschmann Industrial HiVision
Hirschmann Industrial HiVision versions prior to 06.0.07 and 07.0.03 contains an authentication bypass vulnerability in the master service that allows unauthenticated remote attackers to execute arbit...
CVE-2026-0545: Unauthenticated RCE via job endpoints in MLflow
In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled. This vulnerability affects the lates...
CVE-2026-28766: Unauthenticated user account disclosure in Gardyn
A specific endpoint exposes all user account information for registered Gardyn users without requiring authentication....
CVE-2026-32211: Missing authentication in Azure MCP Server
Missing authentication for critical function in Azure MCP Server allows an unauthorized attacker to disclose information over a network....
CIEM — What Is Cloud Infrastructure Entitlement Management?
CIEM (Cloud Infrastructure Entitlement Management) addresses the critical problem of over-permissioned identities in multi-cloud environments. Learn how it works, how it compares to CSPM and CWPP, and best practices for implementation.
ITDR — What Is Identity Threat Detection and Response?
ITDR (Identity Threat Detection and Response) is a security discipline focused on detecting and responding to identity-based attacks. Learn how it works, how it differs from IAM, PAM, and EDR, and why Gartner considers it essential.
RBAC — What Is Role-Based Access Control and How to Implement It
RBAC (Role-Based Access Control) assigns permissions through roles rather than individual users. Learn how it works, how it compares to ABAC, DAC, and MAC, and how to implement it across Active Directory, Azure, and AWS.
What Is Kerberos? Authentication Protocol in Computer Networks
Kerberos is a ticket-based authentication protocol that secures identity verification in computer networks. Learn how it works, its role in Active Directory, common attacks, and defense strategies.
CVE-2026-2699: Unauthenticated configuration access in Citrix ShareFile Storage Zones Controller
Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and potential remote ...
CVE-2026-2701: Authenticated file upload RCE in Citrix ShareFile Storage Zones Controller
Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution....
CVE-2025-15484: Authentication bypass in Order Notification for WooCommerce plugin
The Order Notification for WooCommerce WordPress plugin before 3.6.3 overrides WooCommerce's permission checks to grant full access to all unauthenticated requests, enabling complete read/write acces...
CVE-2025-71279: Passkey authentication compromise in XenForo
XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may be able to compromise the security of Passkey-based authentication....
CVE-2026-20093: Authentication bypass in Cisco Integrated Management Controller
A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to bypass authentication and gain access to the sys...
CVE-2026-20160: Unauthenticated command execution in Cisco Smart Software Manager On-Prem
A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected SS...
CVE-2026-29014: Unauthenticated PHP code injection in MetInfo CMS
MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary code by sending crafted requests with malicious PHP...
CVE-2026-1579: Unauthenticated command execution via unsigned MAVLink in PX4 Autopilot
The MAVLink communication protocol does not require cryptographic authentication by default. When MAVLink 2.0 message signing is not enabled, any message -- including SERIAL_CONTROL, which provides ...
CVE-2026-27049: Authentication bypass in NooTheme Jobica Core
Authentication Bypass Using an Alternate Path or Channel vulnerability in NooTheme Jobica Core jobica-core allows Authentication Abuse.This issue affects Jobica Core: from n/a through <= 1.4.2....
CVE-2026-27084: Deserialization in ThemeREX Buisson buisson
Deserialization of Untrusted Data vulnerability in ThemeREX Buisson buisson allows Object Injection.This issue affects Buisson: from n/a through <= 1.1.11....
CVE-2026-21992: Critical Vulnerability in Oracle Oracle Identity Manager - Immediate Update Required
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Servi...
CVE-2026-20131: unauthenticated RCE as root in Cisco Secure Firewall Management Center (CVSS 10.0)
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management ...
CVE-2026-1603: Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability
Ivanti Endpoint Manager (EPM) contains an authentication bypass using an alternate path or channel vulnerability that could allow a remote unauthenticated attacker to leak specific stored credential d...
What Is LDAP (Lightweight Directory Access Protocol)? A Complete Guide
LDAP (Lightweight Directory Access Protocol) is the foundation of identity management in organizations. Learn how it works, how it differs from Active Directory, and how to secure it.
CVE-2026-20127: Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability
Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, contain an authentication bypass vulnerability could allow an unauthenticated, rem...
CVE-2026-26980: Unauthenticated database read in Ghost CMS
Ghost is a Node.js content management system. Versions 3.24.0 through 6.19.0 allow unauthenticated attackers to perform arbitrary reads from the database. This issue has been fixed in version 6.19.1....
CVE-2026-1731: BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability
BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow an unauthenticated remote attacker to execute opera...
Cyberattack on Polish Energy Sector (December 2025): Lessons for Corporate Boards
The December 2025 cyberattack on Polish energy infrastructure exposed critical vulnerabilities. Discover what happened and the key lessons for every company board.
CVE-2026-24423: SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability
SmarterTools SmarterMail contains a missing authentication for critical function vulnerability in the ConnectToHub API method. This could allow the attacker to point the SmarterMail instance to a mali...
CVE-2026-24858: Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability
Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain an authentication bypass using an alternate path or channel that could allow an attacker with a FortiCloud account and a registere...
CVE-2026-23760: SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability
SmarterTools SmarterMail contains an authentication bypass using an alternate path or channel vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and ...
DORA: One Year In — How It Changed the Financial Sector and Key Takeaways
On January 17, 2025, the DORA regulation became applicable. One year later, we can assess how the regulation has affected the financial sector and what lessons can be drawn for organizations still improving their digital resilience programs.
NIS2 in Poland: Implementation Status — Over a Year Past the Deadline, What's Next?
October 17, 2024 was the deadline for NIS2 implementation. Most EU member states, didn't meet it. What does this mean for organizations and what steps should be taken in the current legal situation?
Social Engineering in Cybersecurity: How Hackers Manipulate People
Social engineering is the most effective method of bypassing security - it attacks the weakest link: humans. Learn what techniques hackers use and how to protect yourself and your organization.
Government Adopted the Draft KSC (NIS2) Amendment — What Does It Mean for Businesses?
The six-year saga surrounding key legislation for the country's cyber security is nearing its finale. The Council of Ministers has adopted a draft amendment to the NSC Act, implementing the NIS2 Directive. Deputy Prime Minister Gawkowski is counting on swift parliamentary proceedings and the preside
Credential Stuffing in E-commerce — How to Protect Customer Accounts
Credential stuffing involves mass login attempts using stolen credentials. Learn how this attack threatens online stores and how to protect customer accounts.
RidgeBot 6.2: Native Directory Brute-Force Scanning, Expanded WAP Support and Unauthenticated SMTP Relay
RidgeBot 6.2 enhances web attack surface coverage with native directory brute-force scanning, extends WAP support to Windows 11 24H2 and Windows Server 2025, and enables report delivery via unauthenticated SMTP relay servers.
CVE-2025-12107: Server-side template injection in WSO2 Identity Server
Security Alert - CVE-2025-12107 (Wso2 Identity Server). CVSS: 10.0 (critical). EPSS: 0%.
Privileged Access Management — How to Control Privileged Access in Your Organization
Privileged accounts are the top attack surface. Learn to implement PAM: password vaults, just-in-time access, session recording, and CIEM in the cloud for security.
Lessons from the biggest data leaks 2024/2025: how to avoid the mistakes of the biggest companies?
Every high-profile data leak is a free, albeit painful, lesson in cyber security for the rest of the world. The incidents that rocked major corporations in 2024 and 2025 show that even gigantic budgets don't protect against basic mistakes. We analyze what really failed and what lessons every CISO an
Zero Trust in OT Networks: Can the "Trust No One" Principle Work in a Factory with PLCs?
Zero Trust is a revolution in cyber security, but how do you implement the
What is a password manager and why is it essential for security?
Passwords are the first line of defense and also the weakest link in any company's security. Employees, overwhelmed by the number of accounts, write them down on pieces of paper or use the same simple combinations everywhere. This guide is an in-depth analysis of the problem and its solution. We exp
Identity management in the digital age - A comprehensive guide
In the digital world, identity is the new security perimeter. It is no longer
End of Windows 10 support: 7 key steps for a safe and effective migration to Windows 11
Learn how to prepare for the end of Windows 10 support in 2025 and smoothly migrate to Windows 11, minimizing risks and costs.
Cyber security in SMEs: How to protect small businesses from cyber threats?
What cyber threats affect SME companies and how to protect against them?
Low-Code Platform Security: Risks and strategies for protecting citizen developers' applications
Low-code platforms make it easier to develop applications, but require effective protection against threats and vulnerabilities.
RidgeBot 5.0: A Breakthrough in Automated Web API Security Testing
RidgeBot 5.0 is the first automated penetration testing platform that natively supports HTTP-based API testing. It detects OWASP API Top 10 vulnerabilities, Broken Authentication, hidden API paths, and other threats with zero false positives.
Personal Data Breach — Action Instructions: A Comprehensive Step-by-Step Guide
Learn how to act in case of a personal data leak to minimize its effects and protect your organization.
Two-Factor Authentication (2FA) - Why Use It and How to Implement
Learn why two-factor authentication (2FA) is worth using and how to implement it for better data protection.
What is Spoofing? Types, Operation and Techniques. How to Protect Yourself?
Spoofing is a serious threat in the world of cybercrime, using identity forgery techniques to deceive users and systems.
What Are the Penalties for Non-Compliance with the NIS2 Directive? Guide to Consequences of Violating New Cybersecurity Regulations
Check what sanctions threaten for non-compliance with the NIS2 directive and how to avoid high penalties.
How to Deploy MFA at a University — Multi-Factor Authentication for Staff and Students
Practical guide to deploying multi-factor authentication (MFA) at a university. LDAP/AD integration, method selection, and rollout for thousands of users.
How to Deploy MFA in a Nonprofit — Step by Step Guide
Multi-factor authentication (MFA) is the single most effective protection against account takeover. Learn how to deploy MFA across your nonprofit organization.
KSC NIS2 and cyber insurance: How compliance with the act becomes key to lowering the cost of risk.
Premiums for cyber policies are rising at an alarming rate, and insurers are denying coverage. The KSC/NIS2 directive only exacerbates this trend. For management and CFOs, it sends a message: without documented compliance, not only will you not get a policy, you won't defend yourself against sanctio
GDPR for Foundations and Associations — Obligations and Practical Implementation
Foundations and associations process personal data of donors, beneficiaries, and volunteers. Learn GDPR obligations specific to NGOs and practical ways to fulfill them.
Network access control: capabilities and benefits of FortiNAC
How does FortiNAC provide full control over network access?
Cyberattack on a Production Line: Step-by-Step Scenario and OT Security Lessons
A realistic cyberattack scenario on a factory — from phishing through lateral movement to production shutdown. Analysis of each phase, defense failures and lessons for manufacturing companies.
How to Implement Identity Management (IAM) in Finance
Identity and Access Management (IAM) is the foundation of financial institution security. Learn about IAM architecture, DORA/PCI DSS requirements, and an implementation plan for banks and fintechs.
What Is Authorization? Differences Between Authentication and Access Control
Authorization is the process of verifying a user's permissions to access resources. Learn the differences between authorization and authentication, access control models, and implementation.
ICT Cybersecurity: Comprehensive Guide for Organizations
ICT cybersecurity is the foundation of every modern organization's operation. Learn a comprehensive approach to protecting information and communication systems.
Whistleblower Act — One Year of Application: Practical Conclusions for Organizations
Organizations across Europe have had to implement whistleblowing systems and whistleblower protections. What lessons emerge from the first years of the directive's implementation?
Microsoft 365 and Google Workspace security: 12 steps to protect your data
Your business runs on Microsoft 365 or Google Workspace. This is the center of your communication, collaboration and most valuable data. However, the default configuration of these platforms is just a starting point. What steps should you take to turn them into a secure fortress rather than an open
ZTNA vs VPN: How is Zero Trust Network Access revolutionizing secure remote access?
For years, VPN was synonymous with secure remote access. But in the era of the cloud and working from anywhere, its trust-based model has become a huge risk. ZTNA (Zero Trust Network Access) reverses this philosophy, offering granular, identity-based access to applications rather than the entire net
Network Access Control (NAC): How to regain control over who and what connects to your network.
Your corporate network is like an exclusive club. Do you let anyone who knocks in without checking who they are and whether they follow the rules? Network Access Control (NAC) systems act like a selector at the entrance. They verify the identity of each device and user, check their
KSC NIS2 from the technical side: An Implementation Guide for IT Professionals and Team Leaders
The KSC/NIS2 audit is ready and the board has approved the budget. Now it's time to get to the real work. We explain what implementing
Phishing 2.0 — New Techniques and Protection: How to Defend Against the New Generation of Cyber Fraud
Classic phishing with grammatical errors is becoming a thing of the past. Today we are dealing with Phishing 2.0 - perfectly cloned e-mails, attacks via QR codes and voice fraud enhanced by AI. The threat is more personalized and credible than ever. Are your employees ready for this clash?
Smishing and Vishing — Attack Protection: How to Defend Your Company Against Social Engineering via SMS and Phone
A fake SMS message about an underpaid courier service or a phone call from a supposed bank employee asking for an authorization code - these are now commonplace. Cybercriminals are increasingly abandoning e-mail in favor of more personal and direct attack channels. Smishing and vishing take advantag
Source Code Vulnerability Analysis
Source code vulnerability analysis identifies security gaps in applications and increases software security.
NIS2 deployment strategy: How to build a foundation of compliance and resilience in 90 days?
The NIS2 directive ushers in a new era in cyber security, setting ambitious goals for companies. The key to success is not to act haphazardly, but to adopt a well-thought-out strategy. In this article, we present a proven, practical roadmap for the first 90 days. It's a concrete roadmap that will he
KSC NIS2 and Penetration Testing: Technical Verification as Key Compliance Evidence
You have implemented network segmentation, MFA and EDR. But are you sure there is no vulnerability? KSC/NIS2 requires evidence. We explain why a penetration test is the best tool for the technical team to validate implementation and prove compliance.
IBM LinuxONE - enterprise reliability for Linux workloads
What if you could run Linux on the most reliable hardware ever created? IBM LinuxONE brings mainframe technology to the Linux world.
LegalTech and AI — Adoption in Europe: How Law Firms Are Implementing Artificial Intelligence
Artificial intelligence is revolutionizing the legal industry, but the pace of this revolution varies by country. While Germany and Nordic countries lead the way, Poland remains conservative. How do different countries handle AI adaptation, regulations, and ethics in law?
Remote access to SCADA: How to enable service technicians to work without opening the door for hackers?
It's two in the morning, and a key machine on the production line breaks down. The only specialist who can fix it is 500 kilometers away. Remote access can save production and prevent gigantic losses. But one unsecured connection can also open the door to an attack that will cause an even bigger dis
What is GDPR and how to implement data protection?
GDPR (RODO) is the EU's key data protection regulation. Our guide explains its rules, responsibilities and how to implement effective data protection, building customer trust and avoiding millions in fines with nFlo's help.
What is MEC (Multi-access Edge Computing)? - Definition and applications
In the era of 5G and the Internet of Things (IoT), the traditional cloud computing model is becoming insufficient for applications that require immediate response. Multi-access Edge Computing (MEC) is revolutionizing computing by moving data close to the user. In this article, we explain what this t
How to effectively protect your business from phishing?
Phishing attacks are a daily threat to any organization, leading to financial loss, data leakage and reputational damage. In our comprehensive article, we explain how cybercriminals operate, how to teach employees to recognize threats, and what steps - technical and procedural - you should take to b
What is RODO and how to ensure compliance with data protection?
RODO is not just a legal obligation, but the foundation of trust in business. Discover how to avoid million-dollar fines, what technical measures to implement and how to prepare your company for a breach. See how nFlo supports you in achieving compliance.
What Is VPN (Virtual Private Network) and How to Use It Securely?
VPNs are the foundation of secure remote working. Our guide explains how to protect data on public Wi-Fi networks, what the different protocols are, and how to deploy a secure VPN solution for your business with help from nFlo experts.
Privileged Access Management (PAM): 11 problems and solutions for IT security
Privileged accounts are the digital
What Is CSRF (Cross-Site Request Forgery)? Detection, How It Works, and Prevention
A CSRF attack forces users to unknowingly perform actions in your application. Our guide explains how to detect this vulnerability, how anti-CSRF tokens work, and how an nFlo audit can help you eliminate it.
What is access control and how to secure IT systems?
Access control is the foundation of any company's security. Our guide explains how RBAC and ABAC models work, how to implement the lowest privilege policy and protect your data with the help of nFlo experts.
What is CORS (Cross-Origin Resource Sharing) and how does it work?
: CORS is a fundamental security mechanism in modern web applications. Understand how it works, what
What is FIDO2 and how does modern authentication work?
FIDO2 is the future of login. Understand how passwordless authentication works, why it's phishing-proof, and how to implement it in your company to improve security and convenience. See how nFlo can help you do just that.
What is Brute Force and how to protect against brute force attacks?
The Brute Force attack is a simple but still dangerous method of cracking passwords. Our guide explains how it works, what targets it attacks, and how to implement a multi-layered defense (MFA, account locking) to protect your business with nFlo.
Who is a Data Protection Officer? A complete guide to the role, tasks and responsibilities of the DPO
In the world of RODO, the Data Protection Officer is a key figure - an internal expert, advisor and compliance watchdog. But who is he really and when is his appointment mandatory? This complete guide is an in-depth look at the role of the DPO. We explain his tasks, independence and qualification re
What is a trusted profile and how to use a digital identity securely?
A trusted profile is a digital key to hundreds of public services, from submitting applications to signing official documents. It's a huge convenience, but also a huge responsibility. The theft of your digital identity can have disastrous consequences. This guide is a complete guide to using your tr
What is a TOR network and how to protect a company from the dangers associated with it?
The TOR network, often associated with anonymity and the
Comprehensive PAM Solution – Delinea Secret Server (formerly Thycotic)
Delinea Secret Server (formerly Thycotic Secret Server) is a comprehensive PAM solution for privileged access management. Learn how the tool helps protect sensitive data and ensures access security in your organization.
Privileged Access Management (PAM): How to protect orgaznization
Learn how Privileged Access Management (PAM) protects privileged accounts, minimizing the risk of fraud and cyberattacks.
Zero Trust in Identity Management (IAM): A Defensive Strategy for Modern Organizations
Learn how Zero Trust strategy and identity management (IAM) work together to strengthen an organization's security by continuously verifying access and minimizing risk.
Single Sign-On (SSO): Convenience for employees, security for the company - how to implement
Learn how Single Sign-On (SSO) deployment improves security and user convenience by simplifying access management in the organization.
Strategies for migrating to AWS (
Learn how AWS 6R migration strategies support secure and optimized cloud transformation. Learn methods tailored to different business and technology needs.
ISO 27001 Internal Audit: How to Maximize Benefits for Your Organization
Learn how ISO 27001 internal audits support ISMS improvement by identifying gaps and increasing organizational resilience to threats.
What Is GDPR and How to Practically Apply Its Principles in a Polish Company?
GDPR is not just bureaucracy and marketing consents. It's a fundamental change in the approach to personal data that affects almost every company in Poland. Misunderstanding its principles is a direct path to losing customer trust and multi-million penalties. How to practically translate complicated legal language?
What is legaltech and how is it revolutionizing business legal services?
Legaltech is not just the digitization of law firms. It is a strategic combination of technology, data and processes that automates compliance, contract analysis and risk management, becoming a key support for IT and security departments.
Hardware YubiKey keys in practice: how to implement FIDO2 and hardware MFA in your company step by step
How do YubiKey keys with FIDO2 technology protect a company from account takeover and phishing?
Identity and Access Management (IAM): who, what, where, when and why
Learn how Identity and Access Management (IAM) supports the Zero Trust model, enhancing an organization's security through continuous verification and access control.
API and Web Services Security: How do you effectively protect the digital bridges that connect your applications and data?
Learn how to effectively secure APIs and Web Services from threats. Learn about testing methods, OWASP standards and data protection best practices.
Why is detailed identity and access management (IAM) the foundation of security in AWS?
Learn how to effectively manage access in AWS IAM. Learn best practices and enhance the security of your cloud infrastructure.
Blockchain in cyber security: Applications and benefits for companies
Blockchain enhances corporate security through tamper-resistance and transparent data recording.
API Security: Security in the microservices era
Secure API protects data and systems from attacks through testing, encryption and OWASP compliance.
Edge Computing vs Cloud Computing: A Comparison of Architectures and Applications
Edge computing moves data processing closer to its source, minimizing latency and relieving network stress, while cloud computing centralizes processing in the cloud, offering scalability and flexibility.
Hardware YubiKey Security Keys: What Are They and Why Should You Deploy Them?
How do YubiKey keys enhance corporate security with hardware MFA and FIDO2 protocols?
Physical Servers and Virtualization: A Comprehensive Guide to x86 and RISC Architectures - From Intel/AMD Processors to IBM Power
x86 and RISC servers differ in performance and application. The choice depends on the organization's needs and application workloads.
Guide: How to implement high availability (HA) solutions in your IT infrastructure step by step
High availability (HA) in IT minimizes downtime and ensures service continuity through redundancy and SPOF elimination.
Cybersecurity Mesh: What it is, how it works and its role
Cybersecurity Mesh is a modern approach to IT security, providing flexible and effective protection against cyber threats.
Cybersecurity Mesh Architecture: the future of flexible security systems
Cybersecurity Mesh Architecture is a flexible approach to IT security, integrating different solutions for more effective asset protection.
How does NVMe technology work in data storage? Modern IT infrastructure
NVMe technology is revolutionizing data storage, offering high speed and performance. Check out how it works and the benefits it brings to your business.
What is a rack server and why should you choose one? An essential part of a professional IT infrastructure
Rack servers are the foundation of modern IT infrastructure. Find out what benefits they offer, how to configure them and when they are worth deploying in your company.
RidgeBot: Automated penetration testing and security validation
RidgeBot is an advanced automated penetration testing tool. See how it can help you detect and validate IT security.
AWS vs Azure vs Google Cloud - A comparison of public cloud leaders
AWS, Azure or Google Cloud? Compare the most popular cloud platforms and choose the best solution for your business. Check out the key differences!
Cloud Migration Costs: Budget Planning and Optimization
Migrating to the cloud is an investment worth planning well. Find out how to optimize costs and avoid unforeseen expenses.
What is Mimikatz and how does it work? Key information
Discover what Mimikatz is - a powerful tool used by security professionals and cybercriminals alike to obtain credentials on Windows systems. Learn how it works and the threats it poses to your organization.
What is SSO (Single Sign-On)? - Definition, benefits, technologies, security and costs
Discover what Single Sign-On (SSO) is and how it enables users to access multiple applications with a single set of login credentials, simplifying authentication processes and enhancing security in the digital environment.
Reservation of PESEL number - Key information
Learn what reserving a PESEL number is and how it can protect your personal information from unauthorized use. Learn about the procedure for reserving your PESEL and the situations in which you should consider it.
What is SAML (Security Assertion Markup Language)? Characters
Learn about SAML - Security Assertion Markup Language - an open standard that enables secure exchange of authentication and authorization information ....
What are CRP alert steps? Definition, types, implementation and security procedures
Learn about the CRP alert degrees - levels of cyber threats that help assess risks and implement appropriate protective procedures. Learn what types of these degrees are and what actions should be taken at each of them.
Communication During Penetration Tests: How to Collaborate with Clients
Even the best pentest can be wasted by poor communication. Learn how to build an effective collaboration model, when and what to report, and how to manage expectations.
Active Directory Penetration Testing: Specifics, Techniques, and Attack Paths
Active Directory compromise means taking control of the entire organization. Learn how professional AD penetration tests detect paths to Domain Admin and help secure critical infrastructure.
Scope Creep in Pentesting Projects: How to Avoid Scope Expansion
Scope creep can turn a successful pentest project into costly chaos. Learn how to precisely define scope, manage changes, and avoid common pitfalls.
Veeam Data Cloud for Microsoft Entra ID: Comprehensive Deployment Guide
Learn about Veeam Data Cloud for Microsoft Entra ID - backup-as-a-service for digital identities. Architecture, key features and practical deployment tips.
What is FIDO2 authentication? Definition, operation, application, use and implementation
Discover what FIDO2 is - a modern passwordless authentication standard that enhances security and simplifies the login process. Learn how FIDO2 works, what technologies it uses, and the benefits of implementing it in your organization.
TCP - A Comprehensive Guide to the Transmission Control Protocol: From the Basics to Advanced Mechanisms of Operation
Learn the basics and advanced mechanisms of the TCP protocol, crucial for reliable data transmission in computer networks.
How to check if a phone is hacked? Guide
Learn how to recognize if your phone has been hacked, and learn the steps to help you regain the security of your device.
600 Million Attacks Daily: How to Protect Identities in Microsoft Entra ID?
Digital identities have become the primary target for cybercriminals. Learn what threats lurk for Microsoft Entra ID and how to protect against them.
RidgeBot 6.0: AWS and Windows Pentesting for Enterprise — Next-Gen Security Auditing
RidgeBot 6.0 is a breakthrough version for enterprises, introducing AWS Security Audit and Windows Authenticated Pentest. The platform offers context-aware security validation covering IT, OT, and AI infrastructure.
Backup Microsoft Entra ID: Why Identity Protection Is Essential Today
Microsoft Entra ID is targeted by 600 million attacks daily. Learn about the shared responsibility model and why identity backup has become a critical security element.
What is RPA and how does robotic process automation work in business?
Your skilled employees spend hours copying data between systems and generating the same reports? This is a hidden brake on your company's growth. This guide is an in-depth introduction to Robotic Process Automation (RPA), the technology that allows you to unlock this potential. We explain step-by-st
What is OAuth? Definition, Characteristics, Operation and Challenges
Learn about OAuth – an open authorization standard that enables applications to access user resources without sharing passwords. Discover how this protocol works, what its key components are, and what security and usability benefits it provides.
Data leakage - What it is, how it happens, how to check and where to report it
Learn what a data leak is, how it happens, how to find out if you are affected, and where to report the incident.
What is NFT? Definition, operation, technology and security
Discover what NFT tokens are, how they work and the technologies behind their operation. Also learn about the potential risks and security aspects associated with their use.
What is Phone Spam? How to Recognize and Block It
Learn what phone spam is, how to recognize it, and how to effectively block it to protect your privacy.
What Is a U2F Key and How Does It Work? Key Information
Learn what a U2F key is, how it works, and why it's one of the most secure two-factor authentication methods.
What Are Group Policy Objects (GPO)? - Their Role and Operation
Learn about Group Policy Objects (GPO) in Windows, their role in managing network policies, and the benefits of their use.
What are Group Policies (GPOs)? - Their role and operation
Learn about group policy (GPO) in Windows, their role in managing network policies, and the benefits of using them.
What Is the SHA-256 Algorithm and How Does It Work?
Learn what the SHA-256 algorithm is, how it works, and why it is crucial for cryptographic security.
What is PAM (Privileged Access Management) and How Does It Work?
Learn what PAM (Privileged Access Management) is, how it works, and why it is crucial for IT security.
Cracking - What is It and How Does It Work?
Learn what cracking is, how it works, and why it poses a threat to system and data security.
Sharenting - What It Is, Examples, and Threats
Learn what sharenting is, what threats it poses, and how to responsibly share photos and information about children online.
Vinted Scam - What It Is, How It Works, and How to Avoid It
Learn what a Vinted scam is, how it works, and discover effective protection methods against fraud on the platform.
BPM and Information Security: A Comprehensive Approach to Protecting Business Processes
Learn what BPM is, its applications, and how it supports organizations in optimizing business processes.
Cyberbullying — Types, Consequences, and Defense: What It Is and How to Protect Yourself
Learn about the types of cyberbullying, its effects, and discover how to effectively defend against this threat in the digital world.
Darknet - A Guide to the Hidden Side of the Internet for IT and Cybersecurity Specialists
Discover what darknet is, how it works, and what threats and opportunities are associated with using this hidden part of the internet.
Key Information About Deep Web and Its Significance for Modern IT Infrastructure
Learn the most important information about the deep web – the hidden part of the internet that remains invisible to traditional search engines.
What is Spear Phishing - How It Works, How to Protect Yourself, and How It Differs from Phishing
Learn what spear phishing is, how to defend against this targeted threat, and the differences between it and other forms of phishing.
What is PKI - Public Key Infrastructure? Definition, Key Components, Role, Practical Applications, Standards, Challenges and Benefits
PKI is a public key infrastructure ensuring secure network communication. Learn about its key components and applications.
What is MFA - Multi-Factor Authentication? Definition, Components, Operation, Benefits and Implementation
MFA, or multi-factor authentication, enhances data security through additional layers of protection.
What is Shadow IT? Impact, Examples, Causes, Consequences, Prevention and Building Awareness
Shadow IT refers to unauthorized technologies in companies that can pose data security threats. Learn how to prevent it.
What is Deepfake and How to Defend Against It? - Comprehensive Guide
Deepfake is a technology for falsifying images and audio that can be dangerous. Learn how to effectively defend against it.
National Cybersecurity System Act - Objectives, Definitions, Regulations and Roles
Read about the National Cybersecurity System Act, its objectives, regulations, and roles in protecting IT systems.
What is PCI DSS - Key Facts, Requirements, and Implementation Benefits
Learn about the PCI DSS standard, key to payment card data security. Discover its requirements and benefits of implementation in your organization.
End of CentOS 7: Migration to Red Hat Enterprise Linux — How to Deploy in Your Organization
Support for CentOS 7 has ended. Protect your infrastructure from risk. Our guide explains why RHEL is the natural successor and how nFlo can help with seamless migration.
Source Code Audit - What It Is, How It Works, and Why You Should Do It
Learn how source code auditing can help secure your software against cyber threats. Overview of techniques and benefits.
Common Security Vulnerabilities Detected During Penetration Testing
Common security vulnerabilities detected during penetration testing from nFlo: identify and fix security gaps in your company.
What is WPAD (Web Proxy Auto-Discovery Protocol) and How Does It Work?
WPAD is an outdated protocol that can expose your company to network traffic hijacking. Understand how it works, what risks it creates, and how to disable it to protect your network with nFlo experts.
Conducting Simulated Phishing Campaigns: A Complete Guide
How to conduct simulated phishing campaigns. This nFlo article offers a guide discussing best practices in testing employee readiness for threats.
The Role of Social Engineering in Penetration Testing
The role of social engineering in penetration testing from nFlo: understand and use social engineering techniques. Increase the effectiveness of your security tests.
Privileged Access Management with Fudo Enterprise
Fudo Enterprise offers agentless, easy-to-deploy remote access to servers and applications, providing session monitoring and recording across multiple protocols.
Benefits of Fudo One Implementation for Secure Remote Access for Employees
Fudo One is an advanced Privileged Access Management (PAM) tool that provides secure and controlled remote access to IT resources.
Security in the BEC Era: Threats and Mitigation Strategies
BEC security from nFlo: learn about threats and attack mitigation strategies. Protect your data from cyber attacks.
Passwordless Authentication and Password Vaults
Passwordless authentication and password vaults are the future of access management. Learn how these technologies can increase security and convenience in your company.
Comparison of IBM LinuxONE Rockhopper 4 with Its Predecessor
Learn about the differences between IBM LinuxONE Rockhopper 4 and its predecessor. Discover what new features and improvements Rockhopper 4 offers to increase the performance and security of your IT infrastructure.
Want to implement PAM?
nFlo will help you implement Privileged Access Management, IAM and MFA solutions to protect your organization's critical assets and identities.
Related Topics
Zero Trust
Zero Trust security model - never trust, always verify
SOC
Security Operations Center - 24/7 monitoring and incident response
NIS2
Network and Information Security Directive - requirements for essential entities
ISO 27001
Information security management system - ISMS implementation and certification
Want to Reduce IT Risk and Costs?
Book a free consultation - we respond within 24h
Or download free guide:
Download NIS2 Checklist