Safeguard
Tag

authentication-bypass

Safeguard articles tagged "authentication-bypass" — guides, analysis, and best practices for software supply chain and application security.

33 articles

Vulnerability Analysis

Two More FreePBX CVEs, Six Years Apart, Confirmed Exploited on the Same Day

A 2025 command injection bug in FreePBX's Endpoint Manager and a 2019 authentication bypass landed in KEV together, additional findings beyond FreePBX coverage published elsewhere in this series.

Sep 16, 20265 min read
Vulnerability Analysis

Three Kentico Xperience CVEs Chain Into Pre-Auth RCE Through One Component

Two authentication bypasses and a path traversal bug all target Kentico Xperience's Staging Sync Server, chaining into a documented pre-authentication remote code execution path.

Sep 16, 20265 min read
Vulnerability Analysis

A Perfect-10 Authentication Bypass in Quest's Endpoint Management Appliance

CVE-2025-32975 lets an attacker impersonate any user of Quest KACE Systems Management Appliance without valid credentials, reaching complete administrative takeover.

Sep 16, 20265 min read
Vulnerability Analysis

A Second PaperCut Authentication Bypass, This One Tied to Ransomware

CVE-2023-27351 in PaperCut's SecurityRequestFilter class bypasses authentication with no credentials at all, and CISA flags it with a confirmed ransomware association.

Sep 16, 20264 min read
Vulnerability Analysis

A 2016 SKYSEA Client View Bug Was Confirmed Exploited Nine Years Later

CVE-2016-7836, a critical authentication flaw in a Japanese endpoint management console, sat disclosed for nearly a decade before CISA confirmed active exploitation in October 2025.

Sep 16, 20265 min read
Vulnerability Analysis

Langflow and Marimo: When the AI Platform's Core Feature Is the Vulnerability

Three confirmed-exploited CVEs across Langflow and Marimo show what happens when a code-execution-by-design platform ships an authentication gap on the endpoint meant to guard it.

Sep 16, 20265 min read
Vulnerability Analysis

SmarterMail's Triple Threat: Three Unauthenticated Roads to Full Compromise

In eleven days, SmarterMail picked up three confirmed-exploited CVEs, all unauthenticated, all tied to known ransomware use — file upload, password-reset bypass, and an API missing authentication.

Sep 16, 20265 min read
Vulnerability Analysis

Cisco's Catalyst SD-WAN Line Produced Seven Confirmed-Exploited CVEs in a Year

From a perfect-10 peering authentication bypass to CLI privilege escalation, seven distinct vulnerabilities across Cisco's SD-WAN Controller, Manager, and underlying software were confirmed exploited.

Sep 16, 20264 min read
Vulnerability Analysis

Check Point SmartConsole's Login Bypass Handed Out Real Administrator Tokens

CVE-2026-16232 let an unauthenticated attacker obtain a genuine SmartConsole login token with full administrative privileges — confirmed exploited the same day it was disclosed.

Sep 16, 20264 min read
Vulnerability Analysis

Cisco FMC's Perfect-10 Auth Bypass Sat Unconfirmed for Six Months

CVE-2026-20079, a CVSS 10.0 authentication bypass in Cisco Secure Firewall Management Center, was confirmed exploited six months after its original disclosure.

Sep 16, 20265 min read
Vulnerability Analysis

Two MikroTik RouterOS CVEs, Same Day: When Trust Gets Granted Too Early

MikroTik RouterOS had two vulnerabilities confirmed exploited on the same day in September 2026, both cases of the router extending trust before verification actually completed.

Sep 16, 20264 min read
Vulnerability Analysis

Two Critical NetScaler CVEs, Two Weeks Apart: Memory Overflow and Auth Bypass

Citrix NetScaler ADC and Gateway had two CVSS 9.8 vulnerabilities confirmed exploited in quick succession — a memory overflow and an authentication bypass. Why edge infrastructure keeps accumulating unpatched critical bugs.

Sep 16, 20265 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.