<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Authentication Bypass</title><description>Cybersecurity articles tagged #Authentication Bypass on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>CVE-2026-48710: Kludex Starlette HTTP Smuggling for Auth Bypass</title><link>https://runtimerebel.com/blog/cve-2026-48710-kludex-starlette-http-smuggling-for-auth-bypass</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-48710-kludex-starlette-http-smuggling-for-auth-bypass</guid><description>CVE-2026-48710 impacts Kludex Starlette, enabling HTTP request smuggling and authentication bypass via path injection. Actively exploited.</description><pubDate>Wed, 02 Sep 2026 19:10:47 GMT</pubDate><category>Authentication Bypass</category><category>Active Exploitation</category><category>CVE-2026-48710</category><category>Kludex Starlette</category><category>HTTP Request Smuggling</category></item><item><title>CVE-2026-59822: BerriAI LiteLLM Authentication Bypass</title><link>https://runtimerebel.com/blog/cve-2026-59822-berriai-litellm-authentication-bypass</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-59822-berriai-litellm-authentication-bypass</guid><description>BerriAI LiteLLM is vulnerable to an improper authentication flaw (CVE-2026-59822) actively exploited to bypass authentication.</description><pubDate>Wed, 02 Sep 2026 19:09:55 GMT</pubDate><category>CVE-2026-59822</category><category>BerriAI LiteLLM</category><category>Authentication Bypass</category><category>CISA KEV</category><category>Improper Authentication</category></item><item><title>CVE-2026-84115: Cleo Harmony Auth Bypass Exploit Published</title><link>https://runtimerebel.com/blog/cve-2026-84115-cleo-harmony-auth-bypass-exploit-published</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-84115-cleo-harmony-auth-bypass-exploit-published</guid><description>An exploit is published for CVE-2026-84115, an authentication bypass in Cleo Harmony allowing remote privilege escalation. Immediate patching to v5.8.1.11 is urged.</description><pubDate>Wed, 02 Sep 2026 12:26:27 GMT</pubDate><category>Authentication Bypass</category><category>Privilege Escalation</category><category>Ransomware</category><category>CVE-2026-84115</category><category>Cleo Harmony</category></item><item><title>CVE-2026-82329: JFrog Artifactory Auth Bypass to Admin Tokens</title><link>https://runtimerebel.com/blog/cve-2026-82329-jfrog-artifactory-auth-bypass-to-admin-tokens</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-82329-jfrog-artifactory-auth-bypass-to-admin-tokens</guid><description>Threat actors are exploiting CVE-2026-82329 in JFrog Artifactory, an authentication bypass allowing unauthenticated admin access. Patch immediately.</description><pubDate>Tue, 01 Sep 2026 19:00:04 GMT</pubDate><category>CVE-2026-82329</category><category>JFrog Artifactory</category><category>Authentication Bypass</category><category>Supply Chain Attack</category><category>Exploitation</category></item><item><title>CVE-2026-62911: Exchange Servers Vulnerable to Mailbox Hijack</title><link>https://runtimerebel.com/blog/cve-2026-62911-exchange-servers-vulnerable-to-mailbox-hijack</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-62911-exchange-servers-vulnerable-to-mailbox-hijack</guid><description>Nearly 22,000 Microsoft Exchange Servers remain unpatched against CVE-2026-62911, an auth bypass allowing mailbox hijack attacks.</description><pubDate>Tue, 01 Sep 2026 12:55:00 GMT</pubDate><category>Microsoft Exchange Server</category><category>Authentication Bypass</category><category>Shadowserver</category><category>CVE-2026-62911</category><category>Mailbox Hijack</category></item><item><title>miniOrange SAML SSO Auth Bypass Exploited in WordPress Attacks</title><link>https://runtimerebel.com/blog/miniorange-saml-sso-auth-bypass-exploited-in-wordpress-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/miniorange-saml-sso-auth-bypass-exploited-in-wordpress-attacks</guid><description>Hackers exploit two critical authentication bypasses in miniOrange SAML 2.0 Single Sign On WordPress plugin to gain admin access. Immediate patching is vital.</description><pubDate>Tue, 25 Aug 2026 08:31:42 GMT</pubDate><category>WordPress</category><category>Authentication Bypass</category><category>miniOrange</category><category>SAML</category><category>CVE-2026-61979</category></item><item><title>macOS Screen Sharing Flaw Exploited to Deploy Monero Miner</title><link>https://runtimerebel.com/blog/macos-screen-sharing-flaw-exploited-to-deploy-monero-miner</link><guid isPermaLink="true">https://runtimerebel.com/blog/macos-screen-sharing-flaw-exploited-to-deploy-monero-miner</guid><description>The Netherlands NCSC warns that hackers are actively exploiting an authentication bypass flaw in macOS Screen Sharing to deploy cryptocurrency miners.</description><pubDate>Fri, 14 Aug 2026 16:41:52 GMT</pubDate><category>CVE-2026-65400</category><category>macOS</category><category>Cryptojacking</category><category>Monero</category><category>Authentication Bypass</category></item><item><title>CVE-2026-55040: Critical SharePoint Auth Bypass Exploited After PoC</title><link>https://runtimerebel.com/blog/cve-2026-55040-critical-sharepoint-auth-bypass-exploited-after-poc</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-55040-critical-sharepoint-auth-bypass-exploited-after-poc</guid><description>Attackers exploit CVE-2026-55040, a critical authentication bypass in Microsoft SharePoint, leading to data disclosure and modification.</description><pubDate>Thu, 13 Aug 2026 09:02:53 GMT</pubDate><category>Microsoft SharePoint</category><category>Authentication Bypass</category><category>Zero Day Exploitation</category><category>Proof of Concept</category><category>CVE-2026-55040</category></item><item><title>Microsoft &amp; Apple Patch Critical RCEs and Auth Bypass Flaws</title><link>https://runtimerebel.com/blog/microsoft-apple-patch-critical-rces-and-auth-bypass-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-apple-patch-critical-rces-and-auth-bypass-flaws</guid><description>Microsoft released patches for critical-severity RCE and EoP flaws across Active Directory, Azure, and Teams. Apple fixed a Screen Sharing authentication bypass.</description><pubDate>Sun, 09 Aug 2026 08:32:17 GMT</pubDate><category>Microsoft</category><category>Apple</category><category>Vulnerabilities</category><category>RCE</category><category>Authentication Bypass</category></item><item><title>CVE-2026-18556: N-able N-central Authentication Bypass Actively Exploited</title><link>https://runtimerebel.com/blog/cve-2026-18556-n-able-n-central-authentication-bypass-actively-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-18556-n-able-n-central-authentication-bypass-actively-exploited</guid><description>CISA added CVE-2026-18556 to its KEV catalog, confirming active exploitation of an N-able N-central authentication bypass vulnerability.</description><pubDate>Tue, 04 Aug 2026 17:33:39 GMT</pubDate><category>Authentication Bypass</category><category>CISA KEV</category><category>Exploitation</category><category>CVE-2026-18556</category><category>N Able N Central</category></item><item><title>CVE-2026-18577: Attackers Exploit N-able Patch Bypass</title><link>https://runtimerebel.com/blog/cve-2026-18577-attackers-exploit-n-able-patch-bypass</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-18577-attackers-exploit-n-able-patch-bypass</guid><description>Security teams face active exploitation of CVE-2026-18577, an N-able authentication bypass vulnerability granting administrator access.</description><pubDate>Tue, 04 Aug 2026 01:29:18 GMT</pubDate><category>CVE-2026-18577</category><category>N Able</category><category>Authentication Bypass</category><category>Remote Monitoring and Management</category><category>Vulnerabilities</category></item><item><title>CVE-2026-20316: Cisco Secure FMC Hard-coded Password Vulnerability</title><link>https://runtimerebel.com/blog/cve-2026-20316-cisco-secure-fmc-hard-coded-password-vulnerability</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-20316-cisco-secure-fmc-hard-coded-password-vulnerability</guid><description>CISA confirms active exploitation of CVE-2026-20316, a hard-coded password vulnerability in Cisco Secure Firewall Management Center.</description><pubDate>Fri, 31 Jul 2026 10:42:09 GMT</pubDate><category>CVE-2026-20316</category><category>Cisco Secure Firewall Management Center</category><category>Hard Coded Password</category><category>Authentication Bypass</category><category>CISA KEV</category></item><item><title>VMware Critical Flaws: Auth Bypass, RCE, VM Escapes Patched</title><link>https://runtimerebel.com/blog/vmware-critical-flaws-auth-bypass-rce-vm-escapes-patched</link><guid isPermaLink="true">https://runtimerebel.com/blog/vmware-critical-flaws-auth-bypass-rce-vm-escapes-patched</guid><description>VMware has patched critical vulnerabilities across vCenter, ESX, Workstation, and Fusion, addressing authentication bypass, remote code execution, and VM escapes.</description><pubDate>Thu, 30 Jul 2026 21:12:31 GMT</pubDate><category>VMware vCenter</category><category>VMware ESX</category><category>VMware Workstation</category><category>VMware Fusion</category><category>Authentication Bypass</category><category>Remote Code Execution</category><category>VM Escape</category></item><item><title>PAN-OS GlobalProtect Authentication Bypass Exploited by Qilin</title><link>https://runtimerebel.com/blog/pan-os-globalprotect-authentication-bypass-exploited-by-qilin</link><guid isPermaLink="true">https://runtimerebel.com/blog/pan-os-globalprotect-authentication-bypass-exploited-by-qilin</guid><description>The Qilin ransomware gang is actively exploiting a critical Palo Alto Networks PAN-OS GlobalProtect authentication bypass vulnerability to breach corporate networks.</description><pubDate>Tue, 21 Jul 2026 10:40:15 GMT</pubDate><category>Palo Alto Networks</category><category>PAN OS</category><category>GlobalProtect</category><category>Ransomware</category><category>Qilin</category><category>Authentication Bypass</category><category>VPN</category></item><item><title>n8n Token Exchange Flaw: Impersonation via `sub` Claim Bypass</title><link>https://runtimerebel.com/blog/n8n-token-exchange-flaw-impersonation-via-sub-claim-bypass</link><guid isPermaLink="true">https://runtimerebel.com/blog/n8n-token-exchange-flaw-impersonation-via-sub-claim-bypass</guid><description>A critical token exchange vulnerability in n8n Enterprise allows attackers to impersonate users by leveraging `sub` claim matching across multiple external issuers…</description><pubDate>Thu, 16 Jul 2026 17:23:19 GMT</pubDate><category>N8n</category><category>Token Exchange</category><category>Authentication Bypass</category><category>Impersonation</category><category>JWT</category><category>Workflow Automation</category></item><item><title>F5 BIG-IP and NGINX Vulnerabilities: CVE-2024-41730 and CVE-2024-39475</title><link>https://runtimerebel.com/blog/f5-big-ip-and-nginx-vulnerabilities-cve-2024-41730-and-cve-2024-39475</link><guid isPermaLink="true">https://runtimerebel.com/blog/f5-big-ip-and-nginx-vulnerabilities-cve-2024-41730-and-cve-2024-39475</guid><description>F5 releases critical security updates for BIG-IP and NGINX Plus, addressing authentication bypass, RCE, and memory corruption vulnerabilities.</description><pubDate>Thu, 16 Jul 2026 10:13:07 GMT</pubDate><category>F5 BIG IP</category><category>NGINX Plus</category><category>CVE-2024-41730</category><category>CVE-2024-39475</category><category>Authentication Bypass</category></item><item><title>VMware Avi Load Balancer: Severe Vulnerabilities Enable RCE, Bypass</title><link>https://runtimerebel.com/blog/vmware-avi-load-balancer-severe-vulnerabilities-enable-rce-bypass</link><guid isPermaLink="true">https://runtimerebel.com/blog/vmware-avi-load-balancer-severe-vulnerabilities-enable-rce-bypass</guid><description>VMware has patched 7 severe vulnerabilities in Avi Load Balancer, enabling authentication bypass, RCE, privilege escalation, and directory traversal.</description><pubDate>Tue, 14 Jul 2026 17:22:37 GMT</pubDate><category>VMware</category><category>Avi Load Balancer</category><category>RCE</category><category>Authentication Bypass</category><category>Privilege Escalation</category><category>Directory Traversal</category><category>Patching</category><category>Load Balancer Security</category></item><item><title>Gitea CVE-2026-20896 Authentication Bypass Under Active Exploitation</title><link>https://runtimerebel.com/blog/gitea-cve-2026-20896-authentication-bypass-under-active-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/gitea-cve-2026-20896-authentication-bypass-under-active-exploitation</guid><description>Attackers are exploiting CVE-2026-20896 in Gitea to bypass authentication via HTTP headers, risking unauthorized access to private code and secrets.</description><pubDate>Wed, 08 Jul 2026 10:28:08 GMT</pubDate><category>Gitea</category><category>CVE-2026-20896</category><category>Authentication Bypass</category><category>Active Exploitation</category></item><item><title>BeyondTrust RS/PRA Critical Authentication Bypass Flaws Addressed</title><link>https://runtimerebel.com/blog/beyondtrust-rs-pra-critical-authentication-bypass-flaws-addressed</link><guid isPermaLink="true">https://runtimerebel.com/blog/beyondtrust-rs-pra-critical-authentication-bypass-flaws-addressed</guid><description>BeyondTrust has issued an urgent advisory for critical authentication bypass flaws in Remote Support (RS) and Privileged Remote Access (PRA) software.</description><pubDate>Tue, 07 Jul 2026 11:09:59 GMT</pubDate><category>BeyondTrust</category><category>Remote Support</category><category>Privileged Remote Access</category><category>Authentication Bypass</category><category>Remote Access</category><category>Vulnerability Patch</category></item><item><title>CVE-2026-11405: Tenda Router Firmware Admin Backdoor Exposed</title><link>https://runtimerebel.com/blog/cve-2026-11405-tenda-router-firmware-admin-backdoor-exposed</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-11405-tenda-router-firmware-admin-backdoor-exposed</guid><description>CERT/CC warns of an undocumented admin backdoor, CVE-2026-11405, in Tenda router firmware, enabling full administrative access bypass. Immediate action advised.</description><pubDate>Tue, 07 Jul 2026 11:09:22 GMT</pubDate><category>CVE-2026-11405</category><category>Tenda</category><category>Router</category><category>Firmware</category><category>Authentication Bypass</category><category>Backdoor</category><category>CERT CC</category></item><item><title>CVE-2026-40138: BeyondTrust Pre-Auth Bypass in Remote Support &amp; PRA</title><link>https://runtimerebel.com/blog/cve-2026-40138-beyondtrust-pre-auth-bypass-in-remote-support-pra</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-40138-beyondtrust-pre-auth-bypass-in-remote-support-pra</guid><description>BeyondTrust patched CVE-2026-40138, a critical pre-authentication vulnerability in Remote Support and PRA, enabling unauthenticated device takeover. Patch immediately.</description><pubDate>Tue, 07 Jul 2026 07:46:39 GMT</pubDate><category>CVE-2026-40138</category><category>BeyondTrust</category><category>Remote Support</category><category>Privileged Remote Access</category><category>Authentication Bypass</category><category>Pre Authentication</category></item><item><title>CVE-2026-48558: SimpleHelp OIDC Authentication Bypass &amp; Malware</title><link>https://runtimerebel.com/blog/cve-2026-48558-simplehelp-oidc-authentication-bypass-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-48558-simplehelp-oidc-authentication-bypass-malware</guid><description>Threat actors are actively exploiting CVE-2026-48558, a critical SimpleHelp OpenID Connect authentication bypass vulnerability, to deploy TaskWeaver and Djinn Stealer…</description><pubDate>Tue, 30 Jun 2026 12:48:54 GMT</pubDate><category>CVE-2026-48558</category><category>SimpleHelp</category><category>TaskWeaver</category><category>Djinn Stealer</category><category>Authentication Bypass</category><category>OIDC</category><category>RMM</category></item><item><title>Djinn Stealer Targets Cloud &amp; AI Credentials via SimpleHelp CVE-2026-48558</title><link>https://runtimerebel.com/blog/djinn-stealer-targets-cloud-ai-credentials-via-simplehelp-cve-2026-48558</link><guid isPermaLink="true">https://runtimerebel.com/blog/djinn-stealer-targets-cloud-ai-credentials-via-simplehelp-cve-2026-48558</guid><description>Analysis of Djinn Stealer, an infostealer delivered via critical SimpleHelp CVE-2026-48558, targeting cloud and AI development credentials.</description><pubDate>Tue, 30 Jun 2026 09:19:57 GMT</pubDate><category>Djinn Stealer</category><category>CVE-2026-48558</category><category>SimpleHelp</category><category>Infostealer</category><category>Cloud Security</category><category>AI Credentials</category><category>Authentication Bypass</category></item><item><title>Squidbleed: 29-Year-Old Squid Proxy Bug Leaks Cleartext HTTP Requests</title><link>https://runtimerebel.com/blog/squidbleed-29-year-old-squid-proxy-bug-leaks-cleartext-http-requests</link><guid isPermaLink="true">https://runtimerebel.com/blog/squidbleed-29-year-old-squid-proxy-bug-leaks-cleartext-http-requests</guid><description>A 29-year-old heap over-read vulnerability, dubbed &apos;Squidbleed,&apos; in Squid web proxy&apos;s default configuration can leak cleartext HTTP requests and credentials.</description><pubDate>Mon, 22 Jun 2026 17:36:48 GMT</pubDate><category>Squidbleed</category><category>Squid Proxy</category><category>Heap Over Read</category><category>HTTP Request Leak</category><category>Data Leak</category><category>Authentication Bypass</category></item><item><title>CVE-2024-0012: Critical PAN-OS Management Interface RCE Analysis</title><link>https://runtimerebel.com/blog/cve-2024-0012-critical-pan-os-management-interface-rce-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-0012-critical-pan-os-management-interface-rce-analysis</guid><description>Technical analysis of CVE-2024-0012 affecting Palo Alto Networks PAN-OS. Learn how to detect CVE-2024-0012 exploit and implement immediate mitigation steps.</description><pubDate>Mon, 22 Jun 2026 10:18:47 GMT</pubDate><category>CVE-2024-0012</category><category>Palo Alto Networks</category><category>PAN OS</category><category>RCE</category><category>Authentication Bypass</category></item><item><title>CVE-2023-6110: Rogue Account Creation in SimpleHelp — Patch Now</title><link>https://runtimerebel.com/blog/cve-2023-6110-rogue-account-creation-in-simplehelp-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2023-6110-rogue-account-creation-in-simplehelp-patch-now</guid><description>Attackers can exploit an OIDC implementation flaw in SimpleHelp servers to create unauthorized technician accounts. Immediate update to 5.2.24 is required.</description><pubDate>Tue, 16 Jun 2026 05:57:54 GMT</pubDate><category>SimpleHelp</category><category>CVE-2023-6110</category><category>OIDC</category><category>Remote Management</category><category>Authentication Bypass</category></item><item><title>CVE-2026-0257: Palo Alto Networks PAN-OS GlobalProtect Bypass Active</title><link>https://runtimerebel.com/blog/cve-2026-0257-palo-alto-networks-pan-os-globalprotect-bypass-active</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-0257-palo-alto-networks-pan-os-globalprotect-bypass-active</guid><description>Palo Alto Networks warns of active exploitation of CVE-2026-0257, an authentication bypass flaw in PAN-OS GlobalProtect. Apply critical security patches now.</description><pubDate>Mon, 15 Jun 2026 10:14:42 GMT</pubDate><category>CVE-2026-0257</category><category>Palo Alto Networks</category><category>PAN OS</category><category>GlobalProtect</category><category>Authentication Bypass</category></item><item><title>Chinese Hackers Hijack Auth Flow for Decade-Long Espionage</title><link>https://runtimerebel.com/blog/chinese-hackers-hijack-auth-flow-for-decade-long-espionage</link><guid isPermaLink="true">https://runtimerebel.com/blog/chinese-hackers-hijack-auth-flow-for-decade-long-espionage</guid><description>Chinese state-sponsored hackers maintained long-term access to an isolated network by hijacking the authentication flow, enabling a decade of espionage.</description><pubDate>Sat, 13 Jun 2026 16:36:15 GMT</pubDate><category>Chinese Hackers</category><category>Authentication Bypass</category><category>Long Term Persistence</category><category>Espionage</category><category>Isolated Network</category><category>APT</category></item><item><title>phpBB Authentication Bypass: Admin Login Vulnerability Patched</title><link>https://runtimerebel.com/blog/phpbb-authentication-bypass-admin-login-vulnerability-patched</link><guid isPermaLink="true">https://runtimerebel.com/blog/phpbb-authentication-bypass-admin-login-vulnerability-patched</guid><description>A decade-old authentication bypass in phpBB forum software, affecting versions up to 3.3.11, allowed attackers to log in as any user, including administrators.</description><pubDate>Fri, 12 Jun 2026 20:53:25 GMT</pubDate><category>phpBB</category><category>Authentication Bypass</category><category>Forum Software</category><category>Vulnerability</category><category>Admin Access</category></item><item><title>CVE-2024-21319: PeopleSoft Auth Bypass Exploited by ShinyHunters</title><link>https://runtimerebel.com/blog/cve-2024-21319-peoplesoft-auth-bypass-exploited-by-shinyhunters</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-21319-peoplesoft-auth-bypass-exploited-by-shinyhunters</guid><description>Oracle PeopleSoft zero-day CVE-2024-21319, an authentication bypass, is being actively exploited by ShinyHunters. Patch PeopleSoft 8.59, 8.60, 8.61 now.</description><pubDate>Thu, 11 Jun 2026 17:25:15 GMT</pubDate><category>CVE-2024-21319</category><category>PeopleSoft</category><category>Oracle</category><category>ShinyHunters</category><category>Authentication Bypass</category><category>Zero-Day</category><category>CPU</category></item><item><title>CVE-2026-50751: Critical Check Point VPN Password Bypass Patch Guidance</title><link>https://runtimerebel.com/blog/cve-2026-50751-critical-check-point-vpn-password-bypass-patch-guidance</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-50751-critical-check-point-vpn-password-bypass-patch-guidance</guid><description>Check Point warns of active exploitation of CVE-2026-50751, a critical logic flow flaw in IKEv1 VPN setups allowing unauthenticated password bypass.</description><pubDate>Mon, 08 Jun 2026 17:12:26 GMT</pubDate><category>CVE-2026-50751</category><category>Check Point</category><category>VPN</category><category>IKEv1</category><category>Authentication Bypass</category></item><item><title>CVE-2024-3300: Critical Everest Forms Pro Bypass Leads to Site Takeover</title><link>https://runtimerebel.com/blog/cve-2024-3300-critical-everest-forms-pro-bypass-leads-to-site-takeover</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-3300-critical-everest-forms-pro-bypass-leads-to-site-takeover</guid><description>Hackers are actively exploiting an authentication bypass in the Everest Forms Pro WordPress plugin (CVE-2024-3300). Update immediately to prevent takeover.</description><pubDate>Sat, 06 Jun 2026 16:30:32 GMT</pubDate><category>CVE-2024-3300</category><category>Everest Forms Pro</category><category>WordPress</category><category>Authentication Bypass</category></item><item><title>Hardening Automatic Tank Gauge Systems Against Cyber Threats</title><link>https://runtimerebel.com/blog/hardening-automatic-tank-gauge-systems-against-cyber-threats</link><guid isPermaLink="true">https://runtimerebel.com/blog/hardening-automatic-tank-gauge-systems-against-cyber-threats</guid><description>CISA and partners warn of active cyber threats targeting Automatic Tank Gauge (ATG) systems. Learn to secure critical infrastructure assets now.</description><pubDate>Tue, 02 Jun 2026 21:12:50 GMT</pubDate><category>ATG Systems</category><category>Operational Technology</category><category>ICS Security</category><category>Critical Infrastructure</category><category>CISA Advisory</category><category>Cyber Threat Actors</category><category>Authentication Bypass</category><category>Privilege Escalation</category><category>SQL Injection</category></item><item><title>CVE-2026-8732: WP Maps Pro Admin Creation Vulnerability Exploited</title><link>https://runtimerebel.com/blog/cve-2026-8732-wp-maps-pro-admin-creation-vulnerability-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-8732-wp-maps-pro-admin-creation-vulnerability-exploited</guid><description>Critical vulnerability [CVE-2026-8732] in WP Maps Pro allows unauthenticated attackers to create admin accounts, leading to WordPress site takeovers. Patch immediately.</description><pubDate>Mon, 01 Jun 2026 21:15:33 GMT</pubDate><category>CVE-2026-8732</category><category>WP Maps Pro</category><category>WordPress</category><category>Plugin Vulnerability</category><category>Site Takeover</category><category>Authentication Bypass</category></item><item><title>Palo Alto PAN-OS GlobalProtect VPN: Active Auth Bypass Exploitation</title><link>https://runtimerebel.com/blog/palo-alto-pan-os-globalprotect-vpn-active-auth-bypass-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/palo-alto-pan-os-globalprotect-vpn-active-auth-bypass-exploitation</guid><description>Urgent advisory on the active exploitation of an authentication bypass vulnerability affecting Palo Alto Networks PAN-OS GlobalProtect VPN. Patch immediately.</description><pubDate>Mon, 01 Jun 2026 18:09:49 GMT</pubDate><category>Palo Alto Networks</category><category>PAN OS</category><category>GlobalProtect VPN</category><category>Authentication Bypass</category><category>Active Exploitation</category><category>VPN Vulnerability</category></item><item><title>CVE-2024-5910: Palo Alto GlobalProtect Auth Bypass Exploited - Patch Now</title><link>https://runtimerebel.com/blog/cve-2024-5910-palo-alto-globalprotect-auth-bypass-exploited-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-5910-palo-alto-globalprotect-auth-bypass-exploited-patch-now</guid><description>Palo Alto Networks warns that attackers are exploiting CVE-2024-5910, a critical authentication bypass in GlobalProtect gateway. Learn how to secure your PAN-OS.</description><pubDate>Sat, 30 May 2026 20:26:42 GMT</pubDate><category>CVE-2024-5910</category><category>Palo Alto Networks</category><category>GlobalProtect</category><category>Authentication Bypass</category><category>PAN OS</category></item><item><title>CVE-2026-0257: PAN-OS GlobalProtect Auth Bypass Under Exploitation</title><link>https://runtimerebel.com/blog/cve-2026-0257-pan-os-globalprotect-auth-bypass-under-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-0257-pan-os-globalprotect-auth-bypass-under-exploitation</guid><description>Palo Alto Networks warns of active exploitation of CVE-2026-0257, an authentication bypass vulnerability affecting PAN-OS and Prisma Access GlobalProtect gateways.</description><pubDate>Sat, 30 May 2026 08:54:03 GMT</pubDate><category>CVE-2026-0257</category><category>Palo Alto Networks</category><category>PAN OS</category><category>GlobalProtect</category><category>Prisma Access</category><category>Authentication Bypass</category></item><item><title>CVE-2026-0257: Palo Alto PAN-OS Auth Bypass Under Active Attack</title><link>https://runtimerebel.com/blog/cve-2026-0257-palo-alto-pan-os-auth-bypass-under-active-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-0257-palo-alto-pan-os-auth-bypass-under-active-attack</guid><description>CISA adds CVE-2026-0257, an actively exploited authentication bypass in Palo Alto Networks PAN-OS, to its KEV catalog.</description><pubDate>Fri, 29 May 2026 20:55:29 GMT</pubDate><category>CVE-2026-0257</category><category>Palo Alto Networks</category><category>PAN OS</category><category>Authentication Bypass</category><category>CISA KEV</category><category>Active Exploitation</category></item><item><title>VMware Workspace ONE Access RCE via CVE-2022-22960 — Patch Now</title><link>https://runtimerebel.com/blog/vmware-workspace-one-access-rce-via-cve-2022-22960-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/vmware-workspace-one-access-rce-via-cve-2022-22960-patch-now</guid><description>VMware Workspace ONE Access and Identity Manager face critical RCE vulnerabilities (CVE-2022-22960, CVE-2022-22957) actively exploited.</description><pubDate>Fri, 29 May 2026 05:34:10 GMT</pubDate><category>VMware</category><category>Workspace ONE Access</category><category>Identity Manager</category><category>CVE-2022-22960</category><category>CVE-2022-22957</category><category>CVE-2022-22954</category><category>CVE-2022-22958</category><category>RCE</category><category>SSRF</category><category>Authentication Bypass</category><category>Zero-Day</category></item><item><title>CVE-2026-35616: FortiClient EMS Exploit Delivers EKZ Infostealer</title><link>https://runtimerebel.com/blog/cve-2026-35616-forticlient-ems-exploit-delivers-ekz-infostealer</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-35616-forticlient-ems-exploit-delivers-ekz-infostealer</guid><description>Attackers are actively exploiting CVE-2026-35616, an authentication bypass in FortiClient EMS, to deploy the EKZ infostealer. Protect your organization now.</description><pubDate>Thu, 28 May 2026 20:53:31 GMT</pubDate><category>CVE-2026-35616</category><category>FortiClient EMS</category><category>EKZ Infostealer</category><category>Authentication Bypass</category><category>Credential Stealer</category><category>Fortinet</category></item><item><title>Cisco Catalyst SD-WAN Authentication Bypass: CVE-2026-20182 Exploit</title><link>https://runtimerebel.com/blog/cisco-catalyst-sd-wan-authentication-bypass-cve-2026-20182-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisco-catalyst-sd-wan-authentication-bypass-cve-2026-20182-exploit</guid><description>CISA adds CVE-2026-20182 to its KEV catalog after reports of active exploitation against Cisco Catalyst SD-WAN Controllers. Critical patch required.</description><pubDate>Fri, 15 May 2026 09:11:50 GMT</pubDate><category>CVE-2026-20182</category><category>Cisco</category><category>SD WAN</category><category>CISA KEV</category><category>Authentication Bypass</category></item><item><title>CVE-2024-7109: Burst Statistics WordPress Plugin Auth Bypass Exploited</title><link>https://runtimerebel.com/blog/cve-2024-7109-burst-statistics-wordpress-plugin-auth-bypass-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-7109-burst-statistics-wordpress-plugin-auth-bypass-exploited</guid><description>Hackers are actively exploiting CVE-2024-7109, a critical authentication bypass in Burst Statistics WordPress plugin, to gain admin access. Patch immediately.</description><pubDate>Fri, 15 May 2026 00:52:51 GMT</pubDate><category>Burst Statistics</category><category>WordPress</category><category>Authentication Bypass</category><category>Plugin Vulnerability</category><category>Web Security</category><category>CVE-2024-7109</category></item><item><title>Cisco Catalyst SD-WAN Controller Authentication Bypass via CVE-2026-20182 Exploited in Zero-Day Attacks</title><link>https://runtimerebel.com/blog/cisco-catalyst-sd-wan-controller-authentication-bypass-via-cve-2026-20182-exploited-in-zero-day-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisco-catalyst-sd-wan-controller-authentication-bypass-via-cve-2026-20182-exploited-in-zero-day-attacks</guid><description>Cisco warns of a critical authentication bypass in Catalyst SD-WAN Controller (CVE-2026-20182) actively exploited in zero-day attacks, granting admin access.</description><pubDate>Thu, 14 May 2026 20:36:49 GMT</pubDate><category>Cisco Catalyst SD WAN Controller</category><category>CVE-2026-20182</category><category>Authentication Bypass</category><category>Zero-Day</category><category>SD WAN</category></item><item><title>CVE-2026-20182: Cisco SD-WAN Auth Bypass Actively Exploited</title><link>https://runtimerebel.com/blog/cve-2026-20182-cisco-sd-wan-auth-bypass-actively-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-20182-cisco-sd-wan-auth-bypass-actively-exploited</guid><description>Cisco Catalyst SD-WAN Controller and Manager face critical authentication bypass CVE-2026-20182, actively exploited for admin access. Patch now.</description><pubDate>Thu, 14 May 2026 20:36:04 GMT</pubDate><category>CVE-2026-20182</category><category>Cisco Catalyst SD WAN Controller</category><category>Cisco Catalyst SD WAN Manager</category><category>Authentication Bypass</category><category>SD WAN</category><category>Network Security</category></item><item><title>cPanel CVE-2026-41940 Exploited for Authentication Bypass, Backdoor</title><link>https://runtimerebel.com/blog/cpanel-cve-2026-41940-exploited-for-authentication-bypass-backdoor</link><guid isPermaLink="true">https://runtimerebel.com/blog/cpanel-cve-2026-41940-exploited-for-authentication-bypass-backdoor</guid><description>A critical authentication bypass vulnerability, CVE-2026-41940, in cPanel and WHM is under active exploitation to deploy the Filemanager backdoor.</description><pubDate>Mon, 11 May 2026 20:39:59 GMT</pubDate><category>CVE-2026-41940</category><category>cPanel</category><category>WebHost Manager</category><category>Mr Rot13</category><category>Filemanager Backdoor</category><category>Authentication Bypass</category><category>Active Exploitation</category></item><item><title>CVE-2023-29489: How Attackers Exploit cPanel XSS for Auth Bypass</title><link>https://runtimerebel.com/blog/cve-2023-29489-how-attackers-exploit-cpanel-xss-for-auth-bypass</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2023-29489-how-attackers-exploit-cpanel-xss-for-auth-bypass</guid><description>A critical authentication bypass in cPanel via CVE-2023-29489 is under active exploitation. Discover technical details and essential mitigation steps.</description><pubDate>Mon, 04 May 2026 20:36:54 GMT</pubDate><category>cPanel</category><category>CVE-2023-29489</category><category>Authentication Bypass</category><category>XSS</category><category>Web Hosting</category></item><item><title>MOVEit Automation Critical Authentication Bypass Mitigation Guide</title><link>https://runtimerebel.com/blog/moveit-automation-critical-authentication-bypass-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/moveit-automation-critical-authentication-bypass-mitigation-guide</guid><description>Progress Software has patched a critical authentication bypass in MOVEit Automation. Secure your managed file transfer workflows and sensitive data today.</description><pubDate>Mon, 04 May 2026 20:34:49 GMT</pubDate><category>Moveit Automation</category><category>Progress Software</category><category>Authentication Bypass</category><category>Mft Security</category></item><item><title>CVE-2024-5805: MOVEit Automation Authentication Bypass Mitigation Guide</title><link>https://runtimerebel.com/blog/cve-2024-5805-moveit-automation-authentication-bypass-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-5805-moveit-automation-authentication-bypass-mitigation-guide</guid><description>Progress Software has issued a patch for a critical authentication bypass vulnerability in MOVEit Automation, tracked as CVE-2024-5805 with a CVSS of 9.1.</description><pubDate>Mon, 04 May 2026 12:42:54 GMT</pubDate><category>CVE-2024-5805</category><category>Moveit Automation</category><category>Progress Software</category><category>Authentication Bypass</category><category>MFT</category></item><item><title>CVE-2025-14510: ABB Ability OPTIMAX Azure AD SSO Auth Bypass</title><link>https://runtimerebel.com/blog/cve-2025-14510-abb-ability-optimax-azure-ad-sso-auth-bypass</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-14510-abb-ability-optimax-azure-ad-sso-auth-bypass</guid><description>CISA warns of CVE-2025-14510 impacting ABB Ability OPTIMAX, allowing authentication bypass on Azure AD SSO integrations. Patch immediately.</description><pubDate>Fri, 01 May 2026 00:56:01 GMT</pubDate><category>CVE-2025-14510</category><category>ABB Ability OPTIMAX</category><category>Authentication Bypass</category><category>Azure Active Directory SSO</category><category>ICS</category><category>SCADA</category><category>Energy Sector</category><category>Water and Wastewater</category></item><item><title>CVE-2026-41940: Active Zero-Day Exploitation in cPanel and WHM</title><link>https://runtimerebel.com/blog/cve-2026-41940-active-zero-day-exploitation-in-cpanel-and-whm</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-41940-active-zero-day-exploitation-in-cpanel-and-whm</guid><description>Critical zero-day CVE-2026-41940 in cPanel and WHM allows for authentication bypass. Learn about active exploitation, public PoCs, and essential patch guidance.</description><pubDate>Thu, 30 Apr 2026 12:41:01 GMT</pubDate><category>cPanel</category><category>WHM</category><category>CVE-2026-41940</category><category>Authentication Bypass</category><category>Zero-Day</category></item></channel></rss>