1. CVE-2026-82329: Unauthenticated Administrative Access in JFrog Artifactory via an Empty Cluster Join Key vulnerability | 2026-09-11 00:00 | CVE-2026-82329 | bishopfox.com | original ↗ | #authentication-bypass | #jfrog | #bishop-fox
2. Mind the Config: Detecting and Weaponizing NetScaler CVE-2026-19490 vulnerability | 2026-09-09 00:00 | CVE-2026-19490 | bishopfox.com | original ↗ | #authentication-bypass | #citrix | #netscaler
3. Flexense SyncBreeze – Unauthenticated Remote Code Execution (0DAY-2025-0002) vulnerability | Critical | 2026-08-25 06:58 | crowdfense.com | original ↗ | #rce | #zero-day | #authentication-bypass
4. CVE-2026-61967 — miniOrange OTP Verification Ultimate Member Password Reset Authentication Bypass research | 2026-08-15 00:00 | CVE-2026-61967 | aretiq.ai | original ↗ | #ai-security | #authentication-bypass | #wordpress
5. CVE-2026-55040: SharePoint Server Subscription Edition improper JWT validation lead to Arbitrary Account Login vulnerability | 2026-08-11 05:13 | CVE-2026-55040 | blog.viettelcybersecurity.com | original ↗ | #authentication-bypass | #microsoft | #sharepoint
6. CVE-2026-24031 PoC: Dovecot SQL authentication bypass and user enumeration tool | 2026-08-12 23:19 | CVE-2026-24031 | github.com | original ↗ | #public-poc | #authentication-bypass | #sql-injection
7. A Millisecond of Predictability: Why CVE-2026-11374 Is Hard to Exploit vulnerability | Critical | 2026-07-21 00:00 | CVE-2026-11374 | bishopfox.com | original ↗ | #featured | #vulnerability-research | #account-takeover
8. Authentication Bypass in the default configuration phpBB vulnerability | Critical | 2026-07-04 00:00 | CVE-2026-48611 | aikido.dev | original ↗ | #ai-security | #featured | #account-takeover
9. Detecting CVE-2026-0265 at Scale: PAN-OS CAS Authentication Bypass vulnerability | High | 2026-05-22 00:00 | CVE-2026-0265 | bishopfox.com | original ↗ | #authentication-bypass | #jwt | #palo-alto-networks
10. CVE-2026-45434 — Apache OFBiz LoginWorker checkLogin Password-Change Flow Authentication Bypass RCE research | 2026-05-20 00:00 | CVE-2026-45434 | aretiq.ai | original ↗ | #rce | #authentication-bypass | #cve-2026-45434
11. CVE-2025-32975: The Open Directory Behind the KACE SMA Breach and 60+ Downstream Victims incident | 2026-05-12 00:00 | CVE-2025-32975 | hunt.io | original ↗ | #incident-response | #threat-intelligence | #authentication-bypass
12. API Authentication Bypass in FortiClient EMS 7.4.5-7.4.6–CVE-2026-35616 vulnerability | Critical | Actively exploited | 2026-04-07 00:00 | CVE-2026-35616 | bishopfox.com | original ↗ | #vulnerability-research | #authentication-bypass | #certificate-validation
13. Critical auth bypass in WordPress Azure AD SSO plugin due to missing OIDC id_token validation vulnerability | Critical | 2026-04-10 07:36 | CVE-2026-2628 | yeswehack.com | original ↗ | #cloud | #authentication-bypass | #wordpress
14. The Fragile Lock: Novel Bypasses For SAML Authentication research | 2026-01-21 10:34 | portswigger.net | original ↗ | #appsec | #ruby | #authentication-bypass
15. Fortinet FortiWeb Authentication Bypass – CVE-2025-64446 vulnerability | Critical | Actively exploited | 2025-11-19 00:00 | CVE-2025-64446 | bishopfox.com | original ↗ | #active-exploitation | #vulnerability-research | #authentication-bypass
16. Hacking the World Poker Tour: Inside ClubWPT Gold’s Back Office blog | 2025-10-12 00:00 | samcurry.net | original ↗ | #bug-bounty | #access-control | #authentication-bypass
17. Wiz Research Uncovers Critical Vulnerability in AI Vibe Coding platform Base44 Allowing Unauthorized Access to Private Applications blog | 2025-07-29 14:00 | wiz.io | original ↗ | #ai-security | #cloud-security | #authentication-bypass
18. Golden dMSA: What Is dMSA Authentication Bypass? vulnerability | 2025-07-16 09:30 | semperis.com | original ↗ | #active-directory | #authentication-bypass | #privilege-escalation
19. Unexpected security footguns in Go's parsers blog | 2025-06-18 11:00 | CVE-2020-16250 | blog.trailofbits.com | original ↗ | #authentication-bypass | #deserialization | #go
20. Vibe Hacking: Finding Auth Bypass and RCE in Open Game Panel research | 2025-04-30 05:52 | CVE-2025-15586 | projectblack.io | original ↗ | #rce | #authentication-bypass | #open-game-panel
21. SAML roulette: the hacker always wins research | 2025-03-31 07:10 | portswigger.net | original ↗ | #gitlab | #authentication-bypass | #xml
22. SonicWall-CVE-2024-53704: Exploit Details vulnerability | 2025-03-21 00:00 | CVE-2024-53704 | bishopfox.com | original ↗ | #authentication-bypass | #exploit | #session-hijacking
23. Prisma and PostgreSQL vulnerable to NoSQL injection? A surprising security risk explained blog | 2025-02-14 00:00 | aikido.dev | original ↗ | #authentication-bypass | #postgresql | #nosql-injection
24. PimpMyBurp #11 – Master Signed Token Exploits with SignSaboteur blog | 2024-11-27 14:00 | yeswehack.com | original ↗ | #burp-suite | #authentication-bypass | #web-security
25. How XBOW Found a Scoold Authentication Bypass vulnerability | 2024-11-14 01:00 | xbow.com | original ↗ | #arbitrary-file-read | #vulnerability-research | #open-source
26. How a GraphQL Bug Resulted in Authentication Bypass vulnerability | 2024-07-29 21:00 | hackerone.com | original ↗ | #bug-bounty | #access-control | #authentication-bypass
27. Looking for vulnerabilities in Strapi (CVE-2024-34065) vulnerability | 2024-06-24 22:00 | CVE-2024-34065 | blog.quarkslab.com | original ↗ | #authentication-bypass | #pentest | #javascript
28. Authentication bypass vulnerabilities in TeamCity: everything you need to know vulnerability | 2024-03-06 16:49 | wiz.io | original ↗ | #cloud | #authentication-bypass | #jetbrains
29. Golang's Improper Error Handling: A Subtle Path to Security Vulnerabilities blog | 2023-11-30 03:41 | hackerone.com | original ↗ | #appsec | #authentication-bypass | #secure-coding
30. Catching bugs in VMware: Carbon Black Cloud Workload Appliance and vRealize Operations Manager vulnerability | 2022-02-25 11:23 | swarm.ptsecurity.com | original ↗ | #cloud | #rce | #authentication-bypass