← BACK TO FEED
TAG

authentication bypass3 articles

N-able's N-central Authentication Bypass Gets Patched Twice After First Fix Left Door Open

Attackers exploited an authentication bypass vulnerability (CVE-2026-18556/CVE-2026-18577) in N-able's N-central remote monitoring platform to gain administrative access to servers and then pivot to managed customer endpoints using the platform's Take Control feature. They also installed persistent Cloudflare tunnels on compromised devices, meaning that simply upgrading N-central is insufficient — customers must also actively hunt for and remove malicious tunnel services. N-able's initial patch proved incomplete, and the fully fixed version (build 2026.3.1.7) was released on August 2, with self-hosted customers required to upgrade manually.

3 Aug 2026

Palo Alto's GlobalProtect Flaw Was Being Actively Exploited Within Days of Disclosure

A high-severity authentication bypass vulnerability (CVE-2026-0257) in Palo Alto Networks' PAN-OS GlobalProtect portal and gateway was patched on May 13, but threat actors began actively exploiting it just four days after public disclosure. Rapid7 observed multiple waves of attacks across customer environments, with attackers using forged cookies to bypass authentication and, in some cases, gain access to internal networks via VPN. CISA has added the flaw to its Known Exploited Vulnerabilities catalog and is urging federal agencies to apply the available patches by June 1.

1 Jun 2026

Cisco's Latest Perfect 10: Secure Workload Flaw Hands Attackers Admin Privileges for Free

Cisco has disclosed a maximum severity (CVSS 10.0) vulnerability, CVE-2026-20223, in its Secure Workload platform, which allows unauthenticated attackers to gain Site Admin privileges by sending crafted API requests to poorly validated internal REST API endpoints. A successful exploit could enable attackers to read sensitive data and make configuration changes across tenant boundaries, affecting both SaaS and on-premises deployments. Cisco says no workarounds exist, fixed versions have been released, and cloud-hosted deployments have already been patched, though the flaw marks another in a growing string of perfect-10 vulnerabilities from the networking giant.

27 May 2026