Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > Authentication Bypass
#Authentication Bypass

Critical ArangoDB Flaws Enable Login Bypass and Root-Level Code Execution

10 September 2026  |  dark6  |  Vulnerability

Two critical ArangoDB vulnerabilities can be chained to bypass authentication, manipulate database content and execute code with root privileges. Version 3.12.11 contains fixes, and exposed deployments should be...

>> read more

Critical Artifactory Bypass Is Being Used to Mint Administrator Tokens

2 September 2026  |  dark6  |  Vulnerability

A critical JFrog Artifactory authentication bypass is under active exploitation, with attackers reportedly creating administrator tokens on vulnerable servers. Self-hosted customers should upgrade immediately, revoke suspicious credentials and...

>> read more

Ubiquiti Fixes 21 Critical UniFi Flaws Across Routers, Cameras and Access Systems

27 August 2026  |  dark6  |  Vulnerability

Ubiquiti has patched 21 critical vulnerabilities across a broad range of UniFi products, including flaws rated a maximum 10.0. The bugs enable outcomes including authentication bypass, command injection...

>> read more

Actively Exploited SharePoint Flaw Combines With RCE for Server Takeover

26 August 2026  |  dark6  |  Vulnerability

Two on-premises SharePoint vulnerabilities can be chained to bypass authentication and execute code on vulnerable servers. With the authentication flaw already listed as exploited, administrators should patch exposed...

>> read more

Citrix Patches Critical NetScaler Flaw That Lets Attackers Skip the Login Screen Entirely

20 August 2026  |  dark6  |  Vulnerability

Citrix has patched two new NetScaler ADC and Gateway vulnerabilities, including a 9.3-severity authentication bypass that can let remote attackers slip past login controls on SSL VPN, ICA...

>> read more

Five New TP-Link Flaws Let Attackers Hijack ISP-Managed Routers and Mesh Systems

15 August 2026  |  dark6  |  Vulnerability

TP-Link has disclosed five vulnerabilities affecting its carrier-supplied Aginet router, mesh, and modem lineup, the worst of which lets an attacker on the network bypass authentication entirely. Because...

>> read more

SolarWinds Patches Critical Authentication Bypass That Could Unlock Help Desk Portals Without a Login

4 August 2026  |  dark6  |  Vulnerability

SolarWinds has fixed a critical, CVSS 9.8-rated flaw in Web Help Desk that could let attackers bypass SAML single sign-on entirely. Organizations running SAML-based SSO on the platform...

>> read more

Palo Alto GlobalProtect VPN Authentication Bypass CVE-2026-0257 Under Active Exploitation — Patch Now

29 June 2026  |  dark6  |  Vulnerability

Palo Alto Networks has confirmed active exploitation of CVE-2026-0257, a critical authentication bypass in GlobalProtect portal and gateway components that lets unauthenticated attackers establish unauthorized VPN sessions. CISA...

>> read more