daily cyber × ai intelligence

index

tagged

[auth-bypass]

1 edition · 3 items

August 9, 2026 weekly

  • N-able N-central — CVE-2026-18556 / CVE-2026-18577 — god-mode auth bypass, ransomware in play, on KEV, two patches to reach 2026.3.1.10. Horizon3 · Under Active Exploitation
  • Oracle WebLogic — CVE-2026-60206 — CVSS 9.9 SAML auth bypass, public PoC. PoC · Under Active Exploitation
  • N-able ships a third N-central hotfix or an advisory revision for CVE-2026-18556/18577 within 3 weeks, as the Cloudflare Tunnel persistence angle forces scope expansion beyond the auth bypass itself. · Wild Speculation

in Four Labs In, and the First Model Too Dangerous to Ship