Authentication-Bypass
Critical Veeam ONE Flaw Lets Unauthenticated Attackers Coerce SMB Auth From the Service Account
CVE-2026-65641 (CVSS 9.3) lets an unauthenticated network attacker force Veeam ONE's service account into an SMB authentication attempt, exposing Net-NTLM material for relay or offline cracking.
NVIDIA NemoClaw Flaw Lets Any Website Hijack a Local AI Agent via DNS Rebinding
CVE-2026-65105 in NVIDIA NemoClaw lets a single malicious webpage use DNS rebinding to reach an unauthenticated local Ollama instance and permanently poison the model's chat template.
CVE-2026-21962: Max-Severity Oracle HTTP Server / WebLogic Proxy Flaw Added to CISA KEV After Months of Exploitation
CISA added CVE-2026-21962, a CVSS 10.0 auth-bypass and path-traversal flaw in Oracle HTTP Server and the WebLogic Server Proxy Plug-in, to its KEV catalog on August 24 — seven months after Oracle patched it and after mass automated scanning had already begun.
Keycloak's Reset-Credentials Flow Lets Unauthenticated Attackers Take Over Any Account (CVE-2026-18963)
CVE-2026-18963 lets an unauthenticated attacker skip email verification in Keycloak's password-reset flow and set new credentials on any account. Patch to 26.7.2 (or 26.4.15/26.6.6 for Red Hat builds) now.
Phishing the Protocol: How 2026 Attackers Made MFA Irrelevant
Device code grants, app passwords, OAuth consent screens, and WhatsApp device linking all share one property: they're real login flows, not bugs. 2026's biggest identity attacks stopped stealing passwords and started collecting the tokens MFA can't protect.
CVE-2026-69836: Perfect-10 Entra ID Deserialization RCE Exploited in the Wild
Microsoft confirms in-the-wild exploitation of CVE-2026-69836, a maximum-severity unauthenticated deserialization RCE in Entra ID's backend — already patched server-side, but the identity plane behind Microsoft 365 and Azure was exposed with no customer visibility into the attack.
Critical Type Confusion in isolated-vm (GHSA-864f-rcv7-6rh4) Breaks Guest-to-Host Isolation for AI Agent Sandboxes
A type confusion in isolated-vm's ExternalCopy transferList handling lets code running inside a V8 sandbox corrupt host memory and hijack control flow — a full guest-to-host escape in a library millions of AI agent and automation deployments trust to run untrusted code.
Unauthenticated MLflow Webhook SSRF (CVE-2026-64849) Exploited Within Hours to Steal Cloud Credentials
An unauthenticated SSRF in MLflow's webhook-test endpoint, CVE-2026-64849, lets attackers bypass an existing SSRF guard via HTTP redirects to reach cloud metadata services — and exploitation began within hours of the CVE going public.
CVE-2026-19490: Critical NetScaler Auth Bypass Lets Attackers Skip the Login Screen Entirely
A critical CVSS 9.3 authentication bypass in Citrix NetScaler ADC and Gateway lets unauthenticated attackers reach protected resources behind SSL VPN, ICA Proxy, and AAA virtual servers — patch CTX696939 now.
CVE-2026-65400: macOS Screen Sharing Auth Bypass Exploited for Root Access, Added to CISA KEV
CISA added CVE-2026-65400, a pre-auth bypass in macOS Screen Sharing, to its KEV catalog after attackers used it to gain root on internet-exposed Macs and drop Monero miners; CVSS was raised to 9.8 following public PoC release.
CVE-2025-62593: Browser-Based DNS Rebinding RCE in Ray Added to CISA KEV Amid ShadowRay 2.0 Exploitation
CISA has added CVE-2025-62593, a critical DNS-rebinding RCE in the Ray AI compute framework, to its KEV catalog after RondoDox botnet operators weaponized it and ShadowRay 2.0 continued hijacking exposed clusters for GPU cryptomining.
SharePoint JWT Bypass (CVE-2026-55040) Chains With BCS Gadget Chain (CVE-2026-63520) for Unauthenticated RCE
A JWT validation bypass under active exploitation since mid-August now chains with a newly disclosed Business Connectivity Services gadget chain, giving unauthenticated attackers full RCE on on-prem SharePoint farms.
CVE-2026-58231: Max-Severity Unauth RCE in SAP Commerce Cloud Now Under Active Exploitation
CVE-2026-58231, a CVSS 10.0 flaw in SAP Commerce Cloud's Data Hub Adapter, lets unauthenticated attackers execute arbitrary code via a default authentication client. Exploitation attempts began August 14, three days after SAP shipped a patch.
Unpatched GeoServer Zero-Day Lets Unauthenticated Attackers Turn SQL Injection Into RCE
An unpatched, unauthenticated SQL injection in GeoServer's jsonArrayContains filter function is under active probing days after public disclosure, with a documented path to remote code execution on PostgreSQL-backed instances.
Langflow's Third KEV Entry of the Year: CVE-2026-9198 Chains Auto-Login Bypass to Unauthenticated RCE
CVE-2026-9198 chains an unauthenticated auto-login token mint with an unsandboxed code-validation endpoint to give attackers full RCE on default IBM Langflow deployments, now under active exploitation and CISA KEV.
XSS2Shell: WordPress Pre-Auth Login XSS Chains to Full RCE (CVE-2026-64638)
CVE-2026-64638 lets an unauthenticated attacker plant XSS on WordPress's login screen with a single failed-login attempt, then chain DOM clobbering and a REST API JSONP callback to steal an admin's Application Password and execute PHP. Patch to 7.0.3.
Metabase Zero-Day: Unauthenticated SQL Injection (CVSS 10.0) Exploited to Breach Framework and Tally
A pre-auth SQL injection in Metabase's password-reset endpoint let attackers hijack admin access on customer instances, hitting Metabase Cloud tenants Framework and Tally before a patch shipped.
15 TP-Link Omada Flaws Turn Zero-Touch Provisioning Into a Network Takeover Path
Forescout's Vedere Labs found 15 flaws in TP-Link's Omada zero-touch provisioning ecosystem — hardcoded crypto keys, a predictable RC4 cipher, and weak cert validation that chain into full controller and fleet compromise.
N-able's First Patch Didn't Hold: CVE-2026-18577 Bypasses the CVE-2026-18556 Fix for Full N-central Takeover
N-able's emergency fix for an N-central authentication bypass proved incomplete — a new CVE, CVE-2026-18577, lets attackers bypass the patch entirely for unauthenticated 'god-mode' access, and it's being actively exploited against MSPs.
Broadcom Patches Two CVSS 9.8 vCenter Auth Bypass/RCE Flaws and an ESXi VM Escape (VMSA-2026-0006)
Broadcom's VMSA-2026-0006 patches two unauthenticated, CVSS 9.8 vCenter Server flaws (auth bypass and directory-traversal RCE) plus a VMXNET3 VM escape in ESXi — no workarounds exist for either critical vCenter bug.