CVE-2022-40684: Fortinet FortiOS Authentication Bypass Used in StrikeShark
CVE-2022-40684 is an authentication bypass vulnerability in Fortinet FortiOS. It was exploited in the StrikeShark campaign.
CVE-2022-40684 is an authentication bypass vulnerability in Fortinet FortiOS. It was exploited in the StrikeShark campaign.
Microsoft SharePoint is the affected product in CVE-2026-55040, a critical authentication bypass vulnerability. The flaw allows unauthenticated attackers to forge JWT tokens…
Ivanti, Fortinet, and SAP have released security patches addressing multiple critical vulnerabilities that could lead to arbitrary code execution and information disclosure.Fortinet…
An authentication bypass vulnerability in Ivanti Sentry before versions R10.5.2, R10.6.2, and R10.7.1 allows remote unauthenticated attackers to create arbitrary administrative accounts…
Palo Alto Networks has issued an urgent warning regarding active exploitation of a recently disclosed PAN-OS vulnerability, CVE-2026-0257 (CVSS score: 7.8), which…
A high-severity authentication bypass vulnerability in the UpdraftPlus WordPress backup plugin, rated 8.1 by Wordfence. It is now patched and has been…
A path traversal vulnerability in FortiSandbox JRPC API that could allow an unauthenticated attacker to bypass authentication via specially crafted HTTP requests.…
Microsoft researchers have disclosed a novel exploit chain named AutoJack that allows a single malicious web page to hijack an AI browsing…
Missing authentication validation on the /terminal/ws endpoint in Marimo versions 0.20.4 and earlier. Requests could obtain a full pseudo-terminal (PTY) shell and…