<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Unauthenticated Access</title><description>Cybersecurity articles tagged #Unauthenticated Access on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>MikroTik RouterOS Unauthenticated SSH Exploit: Critical Advisory</title><link>https://runtimerebel.com/blog/mikrotik-routeros-unauthenticated-ssh-exploit-critical-advisory</link><guid isPermaLink="true">https://runtimerebel.com/blog/mikrotik-routeros-unauthenticated-ssh-exploit-critical-advisory</guid><description>Attackers are exploiting a critical vulnerability in MikroTik RouterOS via internet-exposed SSH to gain full administrative control without authentication.</description><pubDate>Sun, 06 Sep 2026 11:50:33 GMT</pubDate><category>Unauthenticated Access</category><category>Remote Code Execution</category><category>Zero-Day</category><category>MikroTik</category><category>RouterOS</category></item><item><title>NVIDIA NemoClaw Weakness Allows AI Model Poisoning via Ollama</title><link>https://runtimerebel.com/blog/nvidia-nemoclaw-weakness-allows-ai-model-poisoning-via-ollama</link><guid isPermaLink="true">https://runtimerebel.com/blog/nvidia-nemoclaw-weakness-allows-ai-model-poisoning-via-ollama</guid><description>Oasis Security uncovered a weakness in NVIDIA NemoClaw allowing unauthenticated AI model poisoning through a malicious webpage exploiting Ollama.</description><pubDate>Tue, 25 Aug 2026 16:25:52 GMT</pubDate><category>AI Security</category><category>Unauthenticated Access</category><category>NVIDIA NemoClaw</category><category>Ollama</category><category>DNS Rebinding</category></item><item><title>GitLab GraphQL Flaw CVE-2026-19478: Unauthenticated Project Deletion</title><link>https://runtimerebel.com/blog/gitlab-graphql-flaw-cve-2026-19478-unauthenticated-project-deletion</link><guid isPermaLink="true">https://runtimerebel.com/blog/gitlab-graphql-flaw-cve-2026-19478-unauthenticated-project-deletion</guid><description>GitLab addresses a critical GraphQL flaw (CVE-2026-19478) allowing unauthenticated attackers to delete public projects and user data on self-managed CE/EE instances.</description><pubDate>Tue, 18 Aug 2026 00:39:43 GMT</pubDate><category>Unauthenticated Access</category><category>CVE-2026-19478</category><category>CVE-2026-19650</category><category>GitLab</category><category>GraphQL</category></item><item><title>Metabase Zero-Day Exploited: Unauthenticated Admin Access</title><link>https://runtimerebel.com/blog/metabase-zero-day-exploited-unauthenticated-admin-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/metabase-zero-day-exploited-unauthenticated-admin-access</guid><description>Metabase zero-day vulnerability (CVSS 10.0) actively exploited, allowing unauthenticated remote attackers to gain admin access and steal data.</description><pubDate>Sat, 08 Aug 2026 08:28:26 GMT</pubDate><category>Zero-Day</category><category>SQL Injection</category><category>Unauthenticated Access</category><category>Data Breach</category><category>Metabase</category></item><item><title>MongoBleed: Unauthenticated Credential Theft via Server Memory</title><link>https://runtimerebel.com/blog/mongobleed-unauthenticated-credential-theft-via-server-memory</link><guid isPermaLink="true">https://runtimerebel.com/blog/mongobleed-unauthenticated-credential-theft-via-server-memory</guid><description>Analysis of MongoBleed, a critical vulnerability enabling unauthenticated credential and session token extraction from server memory, highlighting attack surface…</description><pubDate>Wed, 17 Jun 2026 13:27:52 GMT</pubDate><category>MongoBleed</category><category>Attack Surface Management</category><category>Credential Theft</category><category>Session Hijacking</category><category>Unauthenticated Access</category><category>Memory Disclosure</category><category>MongoDB</category></item><item><title>ServiceNow Data Exposure via Unauthenticated API Flaw</title><link>https://runtimerebel.com/blog/servicenow-data-exposure-via-unauthenticated-api-flaw</link><guid isPermaLink="true">https://runtimerebel.com/blog/servicenow-data-exposure-via-unauthenticated-api-flaw</guid><description>ServiceNow warns customers about a security incident after attackers exploited an unauthenticated API vulnerability to access and query customer instance data.</description><pubDate>Wed, 10 Jun 2026 01:03:52 GMT</pubDate><category>ServiceNow</category><category>API Security</category><category>Data Exposure</category><category>Unauthenticated Access</category><category>Cloud Security Incident</category></item><item><title>Oracle April 2026 CPU: 481 Patches for Unauthenticated Flaws</title><link>https://runtimerebel.com/blog/oracle-april-2026-cpu-481-patches-for-unauthenticated-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/oracle-april-2026-cpu-481-patches-for-unauthenticated-flaws</guid><description>Oracle&apos;s April 2026 Critical Patch Update addresses 481 vulnerabilities across 28 product families, including 300+ unauthenticated remote exploits.</description><pubDate>Wed, 22 Apr 2026 08:44:10 GMT</pubDate><category>Oracle</category><category>Cpu April 2026</category><category>Patch Management</category><category>RCE</category><category>Unauthenticated Access</category></item><item><title>Oracle Fusion Middleware RCE Flaw: Immediate Patch Required</title><link>https://runtimerebel.com/blog/oracle-fusion-middleware-rce-flaw-immediate-patch-required</link><guid isPermaLink="true">https://runtimerebel.com/blog/oracle-fusion-middleware-rce-flaw-immediate-patch-required</guid><description>A critical unauthenticated remote code execution (RCE) flaw in Oracle Fusion Middleware&apos;s Identity and Web Services Managers demands immediate patching.</description><pubDate>Fri, 20 Mar 2026 20:12:16 GMT</pubDate><category>Oracle Fusion Middleware</category><category>RCE</category><category>Identity Manager</category><category>Web Services Manager</category><category>Critical Vulnerability</category><category>Unauthenticated Access</category></item></channel></rss>