BleepingComputer·23h ago criticalCISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks#cisa#kev#wso2 7 sources in the wild 2 min1
Cyber Security News·1d ago high16-Year-Old Researcher Finds Microsoft Auth Vulnerability that Exposes 17.3 Trillion Stored Records#microsoft#titan#jwt 4 min1
The Hacker News·10d ago highAttackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution#active-exploitation#asterisk#command-injection in the wild
Cyber Security News·10d ago highCritical WSO2 Vulnerability Allow Hackers to Gain Full Admin Access#api-management#authentication-bypass#cve-2026-5430 3 min
Cyber Security News·10d agoApache Syncope Vulnerabilities Allow Attackers to Execute Malicious Code and Bypass Controls#apache-syncope#code-injection#groovy 3 min3
Cyber Security News·10d ago criticalCritical Issabel PBX Command Execution Vulnerability Exploited in the Wild#asterisk#hardcoded-key#issabel in the wild 3 min1
SecurityWeek·10d ago criticalEnterprises Warned of Attacks Exploiting WSO2 Vulnerability#account-takeover#api-security#authentication-bypass in the wild 2 min2
The Hacker News·11d ago highActive Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens#account-takeover#api-manager#authentication-bypass in the wild 2 min1
oss-security·11d agoCVE-2026-82310: Apache Airflow FAB provider: FAB auth manager: deactivated users retain and renew Core API JWT access#access-control#account-deactivation#apache-airflowCVE-2026-82310
oss-security·12d agoCVE-2026-87802: Apache Syncope: SRA OAuth2 JWT signature verification bypass#apache#cve-2026-87802#jwtCVE-2026-878021
oss-security·12d agoCVE-2026-87785: Apache Syncope: JWT subject spoofing#apache-syncope#authentication-bypass#cveCVE-2026-87785
oss-security·12d agoCVE-2026-78330: Apache Syncope: Privilege escalation for admin user via JWT authentication#apache#cve-2026-78330#jwksCVE-2026-78330
oss-security·12d ago highCVE-2026-73178: Apache Syncope: JWT Access Token takeover#apache#cve#identity-managementCVE-2026-731781
BleepingComputer·15d ago highArtifactory flaws chained in attacks deploying backdoor malware#artifactory#backdoor#exploitation in the wild 2 min2
SecurityWeek·17d ago highFortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension#auth-bypass#chrome-extension#fortimonitoronsight 2 min
Fortinet PSIRT·19d ago highJWT used for authentication in web GUI signed with static key#authentication-bypass#fortimonitoronsight#fortinetAdvisory
Exploit-DB·Aug 17, 2026[webapps] Duplicati 2.2.0.3 - JWT Signing Key Leak#auth-bypass#backup#duplicatiExploit / PoC
The Hacker News·Aug 15, 2026 criticalAttackers Exploit SharePoint Authentication Bypass After Public PoC Release#authentication-bypass#cve-2026-55040#jwt in the wild 3 min
Security Affairs·Aug 13, 2026 highSharePoint CVE-2026-55040 Comes Under Attack Following Public Exploit#authentication-bypass#cve-2026-55040#exploitation in the wild 2 min1
Help Net Security·Aug 13, 2026 criticalAttackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040)#authentication-bypass#cve-2026-55040#jwt in the wild 2 min
The Hacker News·Aug 11, 2026 highResearchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE#ai-agent#jwt#microsoft 3 min1
Rapid7 Blog·Aug 11, 2026 highRapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)#authentication-bypass#cve-2026-55040#jwtCVE-2026-550401