← nejvýznamnější zprávy · všechny zprávy

SPOJENO PŘES CVE EPSS 0.01 (nejvyšší)

Hackers target WordPress sites in miniOrange auth bypass attacks

Classification: Severe, Solution: Official Fix, Exploit Maturity: Proof-of-Concept, CVSSv3.1: 9.8, CVEs: CVE-2026-61979, CVE-2026-15981, Summary: The two vulnerabilities observed in exploitation attempts are tracked as CVE-2026-61979 and CVE-2026-15981 and can be chained together to bypass authentication. Because the miniOrange SAML SSO plugin accepts the signature algorithm from incoming SAML responses instead of enforcing the configured one, an attacker can leverage CVE-2026-61979 to select…

Číst originál na NCSC-FI →

2 zprávy z 2 zdrojů · první 24. 8. 21:26 · poslední 25. 8. 04:00 CZ · EN/orig

WordPress miniOrange FI US

tg: varování tg: zneužíváno tg: zranitelnost tp: identita

CVE v události 2

CVEhodnoceníKEVEPSS
CVE-2026-15981 9.8 3.1 · Wordfence 0.01
CVE-2026-61979 8.1 3.1 · Patchstack 0.00

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 9.8.

Jak se o tom psalo 2

  1. · NCSC-FI FI nadpis události

    Hackers target WordPress sites in miniOrange auth bypass attacks

    Classification: Severe, Solution: Official Fix, Exploit Maturity: Proof-of-Concept, CVSSv3.1: 9.8, CVEs: CVE-2026-61979, CVE-2026-15981, Summary: The two vulnerabilities observed in exploitation attempts are tracked as CVE-2026-61979 and CVE-2026-15981 and can be chained together to bypass authentication. Because the miniOrange SAML SSO plugin accepts the signature algorithm from incoming SAML responses instead of enforcing the configured one, an attacker can leverage CVE-2026-61979 to select…

  2. · BleepingComputer US

    Hackers target WordPress sites in miniOrange auth bypass attacks

    Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators. [...]