Attackers Exploit miniOrange SAML Flaws to Gain WordPress Admin Access
Threat actors are actively exploiting two critical authentication bypass vulnerabilities in the Xecurify miniOrange SAML 2.0 Single Sign On plugin for WordPress.…
Threat actors are actively exploiting two critical authentication bypass vulnerabilities in the Xecurify miniOrange SAML 2.0 Single Sign On plugin for WordPress.…
CVE-2026-15981 is a critical authentication bypass vulnerability in the miniOrange SAML 2.0 Single Sign On plugin. It allows unauthenticated attackers to log…
Cisco has released security updates addressing nine vulnerabilities in its Crosswork platforms and Secure Workload software, with five of the flaws carrying…
Citrix has released security updates to address two vulnerabilities affecting NetScaler ADC and NetScaler Gateway, including a critical authentication bypass flaw that…
CVE-2026-19490 is a critical-severity authentication bypass vulnerability in Citrix NetScaler ADC and NetScaler Gateway. With a CVSS score of 9.3, it affects…
CVE-2021-33044 is an authentication-bypass vulnerability in Dahua IP cameras and related products. Attackers can bypass device identity authentication by constructing malicious data…
CVE-2021-33045 is an authentication-bypass vulnerability in Dahua IP cameras. It involves a loopback login request using the 127.0.0.1 address. The flaw allows…
Cybersecurity researchers at Hunt.io have disclosed a campaign, dubbed Operation CameraSwarm, that compromised more than 14,530 Dahua devices between June 17 and…
A critical vulnerability has been disclosed in the Forminator Forms WordPress plugin, which has over 600,000 active installations. Tracked as CVE-2026-15748 and…
User Profile Builder is a WordPress plugin with over 40,000 active installations, used for managing user registration and profiles. A critical authentication…