Tag: auth bypass flaw

Critical Nginx UI auth bypass flaw now actively exploited in the wild
News

Critical Nginx UI auth bypass flaw now actively exploited in the wild

A serious flaw in the Nginx UI that supports Model Context Protocol (MCP) is already being used in the field to fully take over a server without requiring authentication. The vulnerability, known as CVE-2026-33032, is brought about by nginx-ui leaving the '/mcp_message' endpoint unprotected, which enables remote attackers to use privileged MCP activities without the need for credentials. One unauthenticated request can alter server behavior and essentially take over the web server because those activities entail writing and reloading nginx configuration files. According to NIST's description of the vulnerability in the National Vulnerability Database (NVD), "any network attacker can invoke all MCP tools without authentication, including restarting nginx, creating/modifying/deleti...
Critical infra Honeywell CCTVs vulnerable to auth bypass flaw
News

Critical infra Honeywell CCTVs vulnerable to auth bypass flaw

A serious flaw in certain Honeywell CCTV systems that permits illegal access to feeds or account hijacking is being warned about by the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The security flaw, identified by researcher Souvik Kanda and designated as CVE-2026-1670, is categorized as "missing authentication for critical function" and has a critical severity level of 9.8. The vulnerability permits account takeover and unauthorized access to camera feeds by allowing an unauthenticated attacker to modify the recovery email address linked to a device account. According to CISA, the impacted product has an unauthenticated API endpoint vulnerability that could enable an attacker to remotely modify the "forgot password recovery email address." The following model...
Hackers exploit critical auth bypass flaw in JobMonster WordPress theme
News

Hackers exploit critical auth bypass flaw in JobMonster WordPress theme

A serious flaw in the JobMonster WordPress theme that permits administrator account hijacking under specific circumstances is the focus of threat actors. Wordfence, a WordPress security company, discovered the malicious behavior after thwarting many exploit attempts against its customers during the previous 24 hours. JobMonster is a premium WordPress theme developed by NooThemes that is utilized by candidate search tools, hiring and recruiting portals, and job listing websites. On Envato, the theme has sold over 5,500 copies. The exploited vulnerability has a critical-severity score of 9.8 and is known as CVE-2025-5397. All theme versions up to 4.8.1 are affected by this authentication bypass issue read more about Hackers exploit critical auth bypass flaw in JobMonster WordPress ...