authentication-bypass
Safeguard articles tagged "authentication-bypass" — guides, analysis, and best practices for software supply chain and application security.
33 articles
Two More FreePBX CVEs, Six Years Apart, Confirmed Exploited on the Same Day
A 2025 command injection bug in FreePBX's Endpoint Manager and a 2019 authentication bypass landed in KEV together, additional findings beyond FreePBX coverage published elsewhere in this series.
Three Kentico Xperience CVEs Chain Into Pre-Auth RCE Through One Component
Two authentication bypasses and a path traversal bug all target Kentico Xperience's Staging Sync Server, chaining into a documented pre-authentication remote code execution path.
A Perfect-10 Authentication Bypass in Quest's Endpoint Management Appliance
CVE-2025-32975 lets an attacker impersonate any user of Quest KACE Systems Management Appliance without valid credentials, reaching complete administrative takeover.
A Second PaperCut Authentication Bypass, This One Tied to Ransomware
CVE-2023-27351 in PaperCut's SecurityRequestFilter class bypasses authentication with no credentials at all, and CISA flags it with a confirmed ransomware association.
A 2016 SKYSEA Client View Bug Was Confirmed Exploited Nine Years Later
CVE-2016-7836, a critical authentication flaw in a Japanese endpoint management console, sat disclosed for nearly a decade before CISA confirmed active exploitation in October 2025.
Langflow and Marimo: When the AI Platform's Core Feature Is the Vulnerability
Three confirmed-exploited CVEs across Langflow and Marimo show what happens when a code-execution-by-design platform ships an authentication gap on the endpoint meant to guard it.
SmarterMail's Triple Threat: Three Unauthenticated Roads to Full Compromise
In eleven days, SmarterMail picked up three confirmed-exploited CVEs, all unauthenticated, all tied to known ransomware use — file upload, password-reset bypass, and an API missing authentication.
Cisco's Catalyst SD-WAN Line Produced Seven Confirmed-Exploited CVEs in a Year
From a perfect-10 peering authentication bypass to CLI privilege escalation, seven distinct vulnerabilities across Cisco's SD-WAN Controller, Manager, and underlying software were confirmed exploited.
Check Point SmartConsole's Login Bypass Handed Out Real Administrator Tokens
CVE-2026-16232 let an unauthenticated attacker obtain a genuine SmartConsole login token with full administrative privileges — confirmed exploited the same day it was disclosed.
Cisco FMC's Perfect-10 Auth Bypass Sat Unconfirmed for Six Months
CVE-2026-20079, a CVSS 10.0 authentication bypass in Cisco Secure Firewall Management Center, was confirmed exploited six months after its original disclosure.
Two MikroTik RouterOS CVEs, Same Day: When Trust Gets Granted Too Early
MikroTik RouterOS had two vulnerabilities confirmed exploited on the same day in September 2026, both cases of the router extending trust before verification actually completed.
Two Critical NetScaler CVEs, Two Weeks Apart: Memory Overflow and Auth Bypass
Citrix NetScaler ADC and Gateway had two CVSS 9.8 vulnerabilities confirmed exploited in quick succession — a memory overflow and an authentication bypass. Why edge infrastructure keeps accumulating unpatched critical bugs.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.