miniOrange SAML SSO Bypass Vulnerability

A miniOrange SAML SSO bypass (CVE-2026-61979, CVE-2026-15981) lets attackers forge admin logins on WordPress — and most scanners miss it.

A miniOrange SAML SSO bypass is under active exploitation against WordPress sites, and most vulnerability scanners cannot detect whether a given site is actually affected. Two chained authentication bugs, CVE-2026-61979 and CVE-2026-15981 (CVSS 9.8 each), let an unauthenticated attacker forge a SAML login and access wp-admin as any existing user, including administrators. DigitalOcean confirmed exploitation…

Read More

Top 5 Cybersecurity News Stories April 3, 2026

News Stories April 3

This week’s Top 5 Cybersecurity News Stories April 3, are not a recap, they’re a strategic read of where risk is concentrating. From exploited zero-days and identity chokepoints to collaboration platforms, executive messaging, and ransomware pressure tactics, these signals show how attackers are gaining leverage faster than patch and governance cycles can keep up. Unifying…

Read More