Authentication-Bypass
The Skeleton Key Problem: Why 2026's Worst RCEs All Trace Back to a String Literal
SolarWinds ARM, ManageEngine, ASUS Control Center, Cisco FMC, Dell SCG, and a Tenda router backdoor all failed the same way this year: a secret baked into shipped code instead of generated per install. CWE-798 isn't a legacy bug class — it's still how management planes get owned.
CVE-2026-100706: Kyverno Path-Encoding Bug Lets Any Namespace Tenant Reach Cluster Admin
A validation/execution mismatch in Kyverno's apiCall path handling lets a low-privilege namespace tenant use percent-encoded traversal segments to register a cluster-wide mutating webhook and escalate to cluster admin. CVSS 9.9, fixed in 1.19.1.
CVE-2026-71362: Unauthenticated Account Takeover Hits Adobe Commerce and Magento, Now on CISA KEV
CISA added CVE-2026-71362 to KEV after Sansec confirmed active exploitation. A session-identity bug lets an unauthenticated attacker hijack any customer's Adobe Commerce or Magento account — no credentials, no interaction.
CVE-2026-86708: ManageEngine Shipped a Live GCP Service-Account Key Inside Its Public Installer
CVE-2026-86708 (CVSS 10.0): Zoho's ManageEngine Applications Manager Linux installer shipped a hard-coded, over-privileged Google Cloud service-account key that anyone who downloaded the installer could extract and use to impersonate the account.
CVE-2026-93952: Actively Exploited CVSS 10 Flaw Hands Attackers Privileged Access to Arista's VeloCloud Orchestrator
A maximum-severity input validation flaw in Arista's VeloCloud Orchestrator lets attackers who hold only the public half of an edge device's certificate reach privileged internal functionality on the SD-WAN control plane — and it's already being exploited in the wild.
Verification Theater: The One-Week Pattern Behind BragJack, Plugin4Shell, and WSO2's JWT Bypass
Three unrelated disclosures landed between September 13 and 19, 2026 — a browser AI agent hijack, a Git SHA-pinning bypass in every major coding agent, and a JWT auth bypass under active exploitation. All three share one root cause: a check that confirms a label matches instead of verifying the object it names.
SolarWinds Access Rights Manager CVE-2026-28326: Hard-Coded Key Enables Unauthenticated RCE
A hard-coded cryptographic key in SolarWinds Access Rights Manager (CVE-2026-28326, CVSS 8.8) lets an adjacent-network attacker run arbitrary code with no credentials. Patch to ARM 2026.2.1.
CVE-2026-76460: Maximum-Severity Cisco ISE Auth Bypass Exploited Before Disclosure
CVE-2026-76460 (CVSS 10.0) lets unauthenticated attackers bypass Cisco ISE's web management entirely via a privileged API endpoint and get root — Cisco found it while cleaning up a customer who was already compromised, and CISA added it to KEV within a day.
CVE-2026-59971: MySQL MCP Server's SSE Mode Ships With No Auth, No Host Checks — CVSS 10
CVE-2026-59971 (CVSS 10) in the designcomputer mysql_mcp_server package leaves SSE/HTTP deployments wide open to unauthenticated SQL execution, reachable directly or via DNS rebinding, with no fix required beyond upgrading to 0.4.2.
CVE-2026-5430: Active Exploitation of WSO2 API Manager JWT Bypass Delivers Forged Admin Tokens
Attackers are actively exploiting CVE-2026-5430 (CVSS 9.8), a JWT signature-verification flaw in WSO2 API Manager and its Universal Gateway, to forge tokens carrying administrator privileges — watchTowr's honeypots caught the first forged-admin-token traffic on September 13.
CVE-2026-75754: Chained Flaw in ASUS Control Center Enterprise Gives Unauthenticated Root
CVE-2026-75754 (CVSS 10.0) chains a missing-auth SSRF flaw with hardcoded SSH credentials to hand unauthenticated attackers root on ASUS Control Center Enterprise servers — and everything those servers manage.
Three Strikes: How Cisco's Firewall Brain Became Everyone's Favorite Target
In 2026, Cisco Secure FMC took three separate maximum-severity zero-days — and the third one put a Russian APT and a ransomware affiliate on the same box, in the same weeks, running the same playbook. That convergence is the story, not the CVE.
CVE-2026-85102 & CVE-2026-85103: Dutch NCSC Warns Exploitation of Check Point VPN Certificate RCE Flaws Is Imminent
Two unauthenticated CVSS 9.8 RCE bugs in Check Point's VPN certificate handling have hotfixes since September 9 — the Dutch NCSC says active exploitation is likely imminent even though no public PoC exists yet.
CVE-2026-20079: CVSS 10 Auth Bypass in Cisco Secure FMC Exploited by Sandworm and Qilin Ransomware
A maximum-severity authentication bypass in Cisco Secure Firewall Management Center gives unauthenticated attackers root — Talos has tied active exploitation to Russia's Sandworm and to Qilin ransomware affiliates, and CISA's KEV deadline lands today.
CVE-2026-85706: Unauthenticated CVSS 10 Path Traversal in GitLab's Commits API Under Active Probing
A maximum-severity, unauthenticated path traversal in GitLab's repository commits API lets attackers read arbitrary server files; CISA added it to KEV and honeypots logged probing within hours of the patch.
MikroTrick: Chained MikroTik RouterOS SSH Bugs Give Unauthenticated Root, 122,500 Devices Exposed
CERT Polska's MikroTrick chain (CVE-2026-67276 + CVE-2026-86060) lets attackers bypass SSH authentication and escalate to full admin on MikroTik RouterOS — exploited in the wild since September 2, before patches shipped.
Dell Secure Connect Gateway: Five Chained Flaws Take an Unauthenticated Request to Root
Dell patched five chainable flaws in Secure Connect Gateway, including a token-replay auth bypass and a Docker-socket privilege escalation, that together let an unauthenticated network attacker reach root on the host.
StyleSmuggler: Unpatched Magento/Adobe Commerce Zero-Day Gives Unauthenticated RCE, No Fix Yet
Sansec disclosed StyleSmuggler, an unauthenticated remote code execution chain hitting all current Magento and Adobe Commerce builds, under active attack since September 4 with no CVE and no patch.
CVE-2026-49869: Kestra OSS Auth-Bypass Lets Unauthenticated Attackers Get Root RCE, CISA Sets Today as Federal Deadline
A suffix-match flaw in Kestra OSS's AuthenticationFilter lets anyone skip Basic Auth entirely and reach unauthenticated remote code execution as root, CVSS 10.0, now on CISA's KEV list.
CVE-2026-82329: Critical JFrog Artifactory Auth Bypass Under Active Exploitation for Admin Tokens
Attackers are exploiting CVE-2026-82329, a CVSS 9.8 authentication bypass in JFrog Artifactory, to mint themselves administrator tokens and enumerate credentials on internet-facing build-artifact repositories.