Systematic A/S CPR Access Application IDOR Vulnerability Leads to Danish CPR Register Breach
In early October 2026, threat actors exploited an Insecure Direct Object Reference (IDOR) in Systematic A/S’s CPR access REST API (endpoint /api/v1/cpr/{id}) that lacked role‑based authorization checks. Using a compromised service‑account token obtained via phishing, they enumerated sequential identifiers to exfiltrate approximately 8.8 million CPR records—names, dates of birth, addresses, gender, and CPR numbers—covering virtually the entire Danish population. The breach was detected by a SIEM spike in GET requests, leading to immediate API shutdown, a forensic investigation by Datatilsynet and CERT‑DK, and a Systematic A/S patch (v2.3.1) within 48 hours that added mandatory authorization middleware and enhanced audit logging.
Cisco Catalyst SD-WAN Manager Authentication Bypass CVE-2026-76504
Cisco PSIRT has disclosed CVE-2026-76504, a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager (vManage) affecting multiple release branches. The flaw arises from improper handling of URL-encoded characters within the j_security_check API endpoint, allowing unauthenticated remote attackers to bypass security controls using crafted requests, such as POST /%6a_security_check. Active exploitation has been confirmed in the wild, prompting immediate inclusion in the CISA Known Exploited Vulnerabilities catalog. Successful exploitation grants full administrative control over the SD-WAN control plane, enabling lateral movement and potential compromise of the entire managed network infrastructure. Immediate patching is required as no software workarounds are available.
Critical Authentication Bypass Zero-Day in Cisco Identity Services Engine ISE
A critical zero-day vulnerability, tracked as CVE-2026-76460, is currently being exploited in the wild targeting Cisco Identity Services Engine (ISE) and the ISE Passive Identity Connector (ISE-PIC). Rated with a maximum CVSS score of 10.0, the flaw enables unauthenticated remote attackers to bypass authentication mechanisms, granting unauthorized access to core identity infrastructure. Successful exploitation permits attackers to manipulate Network Access Control (NAC) policies, effectively compromising the entire network admission process. Given the active exploitation and extreme severity, CISA has issued an emergency directive requiring federal agencies to apply security patches by September 19, 2026, to mitigate the risk of full identity infrastructure takeover.
PaperCut NG/MF: Critical Authentication Bypass and RCE Chain CVE-2026-81578 & CVE-2026-82078
PaperCut NG and MF are subject to an active zero-day exploit chain combining an authentication bypass (CVE-2026-81578) and unsafe dynamic class loading (CVE-2026-82078). Attackers leverage the Apache Tapestry framework's 'complex direct' request format to mask administrative calls, bypassing access controls to modify external user-lookup database settings. By injecting malicious JDBC connection strings utilizing Apache Derby's 'foreignViews' and the H2 database's 'INIT' statement, attackers trigger the Nashorn JavaScript engine to achieve unauthenticated Remote Code Execution (RCE) via the pc-app.exe process. Immediate application of the second version of the emergency patch is mandatory to mitigate the risk of full system compromise.
Critical Authentication Bypass in JFrog Artifactory CVE-2026-70548
JFrog Artifactory is currently facing active exploitation of CVE-2026-70548, a critical authentication bypass vulnerability. Unauthenticated attackers are leveraging specific primitives to circumvent security controls and gain unauthorized access to protected artifact paths. This vulnerability enables the exfiltration of proprietary binaries, configuration files, and sensitive build tools, significantly increasing the risk of supply chain contamination. Unlike historical exploits like CVE-2023-46604, which often targeted specific component flaws, this modern bypass facilitates direct access to the Software Development Lifecycle (SDLC) environment, allowing for the injection of malicious code into legitimate software distribution channels. Immediate patching and monitoring for unauthorized artifact access are required to prevent downstream infection.
Oracle WebLogic Server Authentication Bypass CVE-2024-21182
CVE-2024-21182 is a critical authentication bypass vulnerability within the Oracle WebLogic Server Core component. This flaw allows unauthenticated attackers to circumvent security mechanisms via the T3 and IIOP protocols, potentially enabling a full unauthenticated system takeover. Due to confirmed active exploitation in the wild, CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, imposing a mandatory June 4 remediation deadline for federal entities. Failure to patch immediately risks large-scale unauthorized access, confidentiality compromise, and total control of affected WebLogic environments.
Critical Authentication Bypass Vulnerabilities in Xecurify miniOrange SAML WordPress Plugin
Two critical authentication bypass vulnerabilities, CVE-2026-61979 and CVE-2026-15981 (CVSS 9.8), were identified in the Xecurify miniOrange SAML 2.0 Single Sign On WordPress plugin. Attackers exploit flaws in SAML response processing and assertion data manipulation to circumvent Single Sign-On (SSO) logic, allowing unauthenticated actors to assume administrative identities and gain full control of affected WordPress installations. A significant intelligence gap occurred because the plugin's seven product editions share a single identifier (slug), causing premium versions to be omitted from early vulnerability databases while active exploitation was already occurring in the wild. Immediate manual patching and version auditing are required to mitigate risk.