Výsledky hledání

výrobce: miniOrange× typ: varování× v celém archivu zrušit filtry

1 karet z 1 položek CZ · EN/orig

1

Hackers target WordPress sites in miniOrange auth bypass attacks

Classification: Severe, Solution: Official Fix, Exploit Maturity: Proof-of-Concept, CVSSv3.1: 9.8, CVEs: CVE-2026-61979, CVE-2026-15981, Summary: The two vulnerabilities observed in exploitation attempts are tracked as CVE-2026-61979 and CVE-2026-15981 and can be chained together to bypass authentication. Because the miniOrange SAML SSO plugin accepts the signature algorithm from incoming SAML responses instead of enforcing the configured one, an attacker can leverage CVE-2026-61979 to select…

EPSS 0.01 CVSS 9.8 CVE-2026-15981 CVE-2026-61979 WordPress miniOrange FI US 2 zdrojů

tg: varování tg: zneužíváno tg: zranitelnost tp: identita

NCSC-FI · BleepingComputer