Vulnerabilities & Patches
JFrog Artifactory Authentication Bypass Exploited
A JFrog Artifactory authentication bypass is now under active exploitation: attackers are minting themselves unauthenticated administrator tokens on self-hosted Artifactory instances just days after JFrog disclosed the flaw. Tracked as CVE-2026-82329 (CVSS 9.8), the bug sits in Artifactory’s default, out-of-the-box configuration — no misconfiguration required, no credentials needed. What Happened JFrog disclosed the JFrog Artifactory…
Read MoreExchange Authentication Bypass Vulnerability Now Exploitable
A working exploit for an Exchange authentication bypass vulnerability is now public on GitHub, and heise.de reports that roughly 85% of on-premises Exchange servers in Germany remain vulnerable three weeks after Microsoft shipped a fix. The catch: for organizations still running Exchange 2016 or 2019, that fix is locked behind Microsoft’s paid Extended Security Update…
Read MorePaperCut RCE Vulnerability Actively Exploited
A newly disclosed PaperCut RCE vulnerability is already being exploited against PaperCut NG and PaperCut MF print management servers worldwide. PaperCut confirmed active attacks on August 27, 2026, shipped an emergency patch within hours, then replaced it with a hardened second patch the next morning after researchers found the first fix incomplete. Every organization running…
Read MoreminiOrange SAML SSO Bypass Vulnerability
A miniOrange SAML SSO bypass is under active exploitation against WordPress sites, and most vulnerability scanners cannot detect whether a given site is actually affected. Two chained authentication bugs, CVE-2026-61979 and CVE-2026-15981 (CVSS 9.8 each), let an unauthenticated attacker forge a SAML login and access wp-admin as any existing user, including administrators. DigitalOcean confirmed exploitation…
Read MoreGitLab GraphQL code injection vulnerability
A GitLab GraphQL code injection vulnerability is now under active exploitation, reproduced and attacked within minutes of GitLab’s August 17, 2026 disclosure of CVE-2026-19478. The unauthenticated flaw (CVSS 9.4) lets an attacker delete public projects, forge fake fix records, or lock out maintainers on any unpatched self-managed GitLab instance. GitLab.com and GitLab Dedicated were already…
Read More
