vulnerability Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access Attackers are exploiting two unauthenticated vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress, allowing them to gain administrator access to vulnerable sites. The vulnerabilities stem from flaws in signature validation, and a proof-of-concept is available, leading to widespread scanning ac… The Hacker News · 5d ago High CVE-2026-61979CVE-2026-15981wordpresssamlauthentication
vulnerability Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers Citrix has released security updates to address two critical vulnerabilities in NetScaler ADC and NetScaler Gateway, including a high-severity authentication bypass. These flaws primarily affect deployments where specifi… The Hacker News · Aug 20, 2026 High CVE-2026-19489CVE-2026-19490CVE-2026-8451authenticationvpnsaml
vulnerability Multiples vulnérabilités dans les produits Wallix (06 août 2026) Wallix has disclosed multiple vulnerabilities in its Access Manager and Bastion products, potentially allowing attackers to escalate privileges and bypass security policies. These flaws could be exploited to gain unautho… CERT-FR · Aug 6, 2026 Medium vulnerabilitysamlprivilege escalation
threat-intel Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks A Chinese-speaking threat actor, tracked as ‘KnYuan’ and ‘Knaithe’, utilized the Hermes Agent framework and DeepSeek to autonomously launch attacks against over 460 targets. The agent, leveraging Telegram, identified and… The Hacker News · Jul 31, 2026 High CVE-2026-3055CVE-2026-39987CVE-2026-33017CHautonomous attacksvulnerability exploitationtelegram
vulnerability New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure A newly discovered CitrixBleed-like vulnerability (CVE-2026-8451) in NetScaler ADC and Gateways was exploited within 24 hours of its public disclosure. The flaw, stemming from an out-of-bounds read issue in the XML parse… SecurityWeek · Jul 2, 2026 Critical CVE-2026-8451DEHKcitrixbleedsamlmemory disclosure
vulnerability Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service This article details six newly discovered vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway software, potentially allowing for denial-of-service attacks and arbitrary file reads. The vulnerabilities, ranging… The Hacker News · Jul 1, 2026 High CVE-2026-8451CVE-2026-8452CVE-2026-8655samlhttp2memory
vulnerability SAP fixes critical flaws in NetWeaver and Commerce Cloud SAP has released a security patch addressing 15 vulnerabilities across its NetWeaver and Commerce Cloud platforms. The patch includes four critical flaws, primarily focused on authentication bypass and memory corruption,… BleepingComputer · Jun 9, 2026 Critical CVE-2026-44748CVE-2026-27671CVE-2026-22732samsauthenticationmemory corruption