
CVE-2026-55040 SharePoint Authentication Bypass: Patch Now
CVE-2026-55040 SharePoint JWT bypass gives attackers admin access without credentials. CISA KEV-listed and actively exploited: patch KB5002882 today.
In-depth analyses of zero-day vulnerabilities, CVE exploits, ransomware campaigns, and nation-state attack techniques affecting enterprise security. Filter by category, tag, or keyword.
Every article here lands in subscribers' inboxes the morning it drops.
Threat intel, active CVEs, and campaign alerts, distilled daily for practitioners. 50,000+ subscribers. No noise.
Free. No spam. Unsubscribe anytime.
The definitive practitioner breakdown of ZTA principles, pillars, and implementation sequence.
Containment, forensic preservation, and decision sequencing from detection to recovery.
How SIEMs ingest, correlate, and alert — and how to evaluate one for your environment.
Risk-based prioritization using CVSS, EPSS, and CISA KEV to cut remediation backlog.
What each risk means, how to reproduce it, and how to fix it in production code.
Step-by-step email authentication deployment from DNS records to p=reject enforcement.
Detection coverage, pricing, and deployment trade-offs for enterprise EDR selection.
Translate ATT&CK technique IDs into detection rules and threat actor hunting hypotheses.
Direct answers to the questions practitioners and AI systems ask most. Covers ransomware, identity, cloud, compliance, and detection.
Plain-language definitions for CVE, SIEM, SOAR, Zero Trust, EDR, and 85+ other terms used in enterprise security.
How-to guides, buyer comparisons, and methodology references across every major security domain.
Decryption Digest Response
Score every threat we cover against your own stack, get free Sigma and ModSecurity detection content, and upgrade anytime for more vendors.
Get started free →No card required. Sigma and ModSecurity rules are free, forever.
Win an All Access InfoSec World 2026 pass, valued at $3,895.
Win a $3,895 InfoSec World 2026 pass.
15 results tagged authentication bypass

CVE-2026-55040 SharePoint JWT bypass gives attackers admin access without credentials. CISA KEV-listed and actively exploited: patch KB5002882 today.

N-central CVE-2026-18577 authentication bypass is actively exploited, giving attackers god-mode RMM access. Plus Qilin PAN-OS ransomware and $88.6M COLDCARD heist.

Qilin ransomware exploits CVE-2026-0257 PAN-OS GlobalProtect bypass to breach healthcare and manufacturing. 167K firewalls exposed. Patch to 10.2.10 or 11.0.5 now.

CVE-2026-8451 hit Citrix NetScaler ADC within 24 hours of disclosure. 71 IPs logged 424 exploitation signals targeting SAML session tokens.

Check Point VPN authentication bypass CVE-2026-50751 scores CVSS 9.3. Qilin ransomware is actively exploiting it. Patch before EOD.

cPanel CVE-2026-41940 has compromised 44,000 servers worldwide. Four more critical vulnerabilities demand your Monday morning action.

Cisco SD-WAN authentication bypass CVE-2026-20182 scores CVSS 10.0 with CISA KEV status and active exploitation by UAT-8616. No workaround, patch now.

CVE-2024-37085 is an authentication bypass (CVSS 6.8) in VMware ESXi that allows a domain user who is a member of an Active Directory group named 'ESX Admins' to gain full administrative access to the ESXi hypervisor, regardless of whether that group was explicitly configured for ESXi access. Exploited by at least five ransomware groups (Black Basta, Akira, Medusa, RansomHub, and Scattered Spider) to target ESXi hosts directly, encrypting VM storage files and achieving mass disruption across virtualised environments.

CVE-2024-1709 is a CVSS 10.0 authentication bypass in ConnectWise ScreenConnect (< 23.9.8). An extra trailing slash in the URL path bypasses authentication middleware, allowing an unauthenticated attacker to execute the setup wizard and create a new administrator account. Exploited by LockBit, Black Basta, and multiple ransomware groups within 48 hours of disclosure. Affects all ScreenConnect on-premises deployments below version 23.9.8.

CVE-2023-46805 is an authentication bypass (CVSS 8.2) in Ivanti Connect Secure and Policy Secure. Chained with CVE-2024-21887, a command injection (CVSS 9.1), it produces unauthenticated remote code execution on the VPN gateway. Exploited as a zero-day by suspected Chinese state-sponsored actor UNC5221 for at least two weeks before disclosure. CISA issued Emergency Directive 24-01 ordering federal agencies to disconnect or mitigate within 48 hours. Over 2,100 devices were compromised globally before patches were available.

CVE-2023-42793 is a CVSS 9.8 authentication bypass in JetBrains TeamCity (< 2023.05.4) allowing an unauthenticated attacker to generate an admin-level API token with a single HTTP request. Full remote code execution follows via plugin upload. Exploited by North Korea's Lazarus Group, Russia's COZY BEAR (APT29), and multiple ransomware operators for CI/CD pipeline compromise and software supply chain attacks.

CVE-2023-32315 is a critical path traversal vulnerability in the Openfire XMPP messaging server admin console (versions 3.10.0 through 4.7.4), patched in May 2023. An unauthenticated attacker can access the admin console setup wizard by bypassing the authentication filter via a URL path traversal, then upload a malicious Openfire plugin containing arbitrary Java code. Over 3,000 servers were compromised in active exploitation campaigns observed through mid-2023.

CVE-2022-1388 is a critical authentication bypass vulnerability in the F5 BIG-IP iControl REST management API. Unauthenticated attackers with network access to the management interface can execute arbitrary OS commands as root by manipulating HTTP headers to bypass the API authentication layer. Mass exploitation began within 24 hours of F5's advisory. CISA and FBI issued a joint advisory warning of active exploitation.

CVE-2021-40539 is a critical authentication bypass and remote code execution vulnerability in ManageEngine ADSelfService Plus (versions before build 6114), patched in September 2021. The flaw allowed unauthenticated attackers to access protected REST API endpoints and upload a JSP webshell, achieving code execution on the server. APT41 and at least two other threat actor clusters exploited it against U.S. defense contractors, academic institutions, and critical infrastructure. CVSS 9.8.
CVE-2020-14882 is a critical authentication bypass in the Oracle WebLogic Server web-based administration console. Chained with CVE-2020-14883, it enables unauthenticated remote code execution on one of the most widely deployed Java EE application servers in enterprise environments. Exploitation began within days of Oracle's October 2020 Critical Patch Update and was adopted by nation-state actors and ransomware operators.