The Canadian Centre for Cyber Security published 7 security advisories on July 16, 2026, covering Zoom, Splunk, JetBrains, Grafana, Microsoft, and Fortinet products. The most critical items are three Microsoft CVEs (CVE-2026-56164, CVE-2026-56155, CVE-2026-58644) and three Fortinet FortiSandbox CVEs (CVE-2026-25089, CVE-2026-39813, CVE-2026-39808) that have been confirmed as actively exploited and added to CISA's Known Exploited Vulnerabilities database. Splunk Enterprise also has critical vulnerabilities including a CSRF-based SPL command bypass and a path traversal in the App Install REST endpoint.
Authentication Bypass
16 posts
Cyber Centre Daily Advisory Digest — 2026-07-16 (7 advisories) 13th July – Threat Intelligence Report This weekly threat intelligence bulletin covers multiple significant incidents including autonomous LLM-driven ransomware (JadePuffer), a cryptocurrency supply chain compromise via malicious npm packages, and three critical CVEs affecting Langflow, Tenda routers, and Linux KVM. Iran-linked Cavern Manticore and China-linked UAT-7810 were profiled targeting Israeli and networking infrastructure respectively. The report also highlights risks in AI development tools where hidden malicious instructions in open-source files could achieve RCE through Claude Code and OpenAI Codex.
The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI Mandiant discovered that ADFS environments with AutoCertificateRollover disabled and manually rotated certificates can expose active token-signing private keys in Machine DPAPI storage, creating a 'ghost certificate' drift condition where the WID database contains stale entries. A SYSTEM-level attacker can recover the active signing key from the machine CAPI key store using the DPAPI_SYSTEM LSA secret and machine masterkeys, bypassing LSASS and ADFS process monitoring. The recovered key enables forging valid SAML assertions for any user, including Global Administrator, which Entra ID accepts as legitimate authentication.
StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader The StrikeShark campaign utilizes a novel malware family named SharkLoader to deploy Cobalt Strike Beacons across various global sectors. Threat actors gain initial access by exploiting known vulnerabilities in public-facing applications or distributing custom droppers disguised as legitimate software. SharkLoader employs advanced evasion techniques, including Perfect DLL Hijacking and extensive API hooking, to bypass loader locks and conceal its execution in memory.
Rockwell Automation FLEX I/O EtherNet/IP Adapters (CVE-2026-0646, CVE-2026-0647) Rockwell Automation FLEX I/O EtherNet/IP Adapters version 2.012 are affected by two vulnerabilities. CVE-2026-0647 allows unauthenticated account takeover via the embedded web server, while CVE-2026-0646 enables a denial-of-service condition through malformed CIP protocol requests.
AL25-019 - Vulnerabilities impacting Fortinet products - FortiCloud SSO Login Authentication Bypass - CVE-2025-59718 and CVE-2025-59719 - Update 2 Critical vulnerabilities in Fortinet products allow unauthenticated attackers to bypass FortiCloud SSO and SAML login authentication using crafted SAML response messages. Active exploitation has been observed in the wild, necessitating immediate patching or the disabling of the FortiCloud SSO feature and restriction of internet-facing administrative access.
Marking Your Own Homework (Check Point Remote Access VPN IKEv1 Authentication Bypass CVE-2026-50751) Check Point Remote Access VPNs are vulnerable to a critical authentication bypass (CVE-2026-50751, CVSS 9.3) within the IKEv1 key exchange process. By sending a crafted 'VPNExtFeatures' Vendor ID payload, an attacker can manipulate the negotiation state to skip certificate signature verification, allowing full network access using only a valid username and the gateway's public ICA organization string.
Arctic Wolf Observes an Increase in Palo Alto Networks GlobalProtect Authentication Bypass Exploitation via CVE-2026-0257 Arctic Wolf Labs observed an ongoing campaign exploiting CVE-2026-0257, a high-severity authentication bypass vulnerability in Palo Alto Networks GlobalProtect. Threat actors are forging authentication override cookies to establish unauthorized VPN sessions, followed by rapid internal network reconnaissance using Impacket tooling.
Security Advisory 2026-008 Ivanti has disclosed two critical vulnerabilities in its Sentry products, including an OS command injection flaw (CVE-2026-10520) and an authentication bypass vulnerability (CVE-2026-10523). These vulnerabilities allow remote, unauthenticated attackers to achieve root-level remote code execution and create arbitrary administrative accounts on affected devices.
CISA Adds Two Known Exploited Vulnerabilities to Catalog (CVE-2026-42271, CVE-2026-50751) CISA has added CVE-2026-42271 (BerriAI LiteLLM Command Injection) and CVE-2026-50751 (Check Point Security Gateway Improper Authentication) to the Known Exploited Vulnerabilities (KEV) catalog due to active exploitation. Organizations are strongly urged to prioritize remediation of these vulnerabilities to reduce exposure to cyberattacks.
CISA Adds One Known Exploited Vulnerability to Catalog - CVE-2026-20182 CISA has added CVE-2026-20182, an authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Controllers, to its Known Exploited Vulnerabilities (KEV) catalog due to evidence of active exploitation. Federal agencies and private organizations are strongly urged to apply mitigations outlined in Emergency Directive 26-03 or discontinue use of the product if mitigations are unavailable.
The Internet Is Falling Down, Falling Down, Falling Down (cPanel & WHM Authentication Bypass CVE-2026-41940) cPanel and WHM are vulnerable to a critical authentication bypass (CVE-2026-41940) that allows unauthenticated attackers to gain root-level access. The flaw stems from a CRLF injection vulnerability in session file handling, enabling attackers to forge session attributes and bypass password validation mechanisms by manipulating the whostmgrsession cookie and Basic Authentication headers.
You’re Not Supposed To ShareFile With Everyone (Progress ShareFile Pre-Auth RCE Chain CVE-2026-2699 & CVE-2026-2701) Security researchers discovered a pre-authenticated Remote Code Execution (RCE) chain in Progress ShareFile Storage Zone Controller. By chaining an Execution After Redirect (EAR) authentication bypass (CVE-2026-2699) with an arbitrary file upload vulnerability (CVE-2026-2701), attackers can reconfigure the storage repository to the webroot and extract an ASPX webshell, achieving full system compromise.
Security Advisory 2026-002 Cisco has disclosed multiple critical and high-severity vulnerabilities affecting Catalyst SD-WAN Controller and Manager, including CVE-2026-20127, a CVSS 10 authentication bypass exploited in the wild since 2023. Successful exploitation allows unauthenticated remote attackers to gain administrative privileges, manipulate network configurations, and establish persistent access, sometimes by downgrading software to exploit older vulnerabilities.
AL26-004 - Critical vulnerability affecting Cisco Catalyst SD-WAN - CVE-2026-20127 The Canadian Centre for Cyber Security has issued an alert regarding the active exploitation of CVE-2026-20127, a critical improper authentication vulnerability affecting Cisco Catalyst SD-WAN Controller and Manager systems. Unauthenticated remote attackers can exploit this flaw to bypass peering authentication, gain administrative privileges, and add malicious rogue peers to the network configuration for long-term persistence.
AL26-002 -Vulnerability affecting GNU Inetutils Telnetd - CVE-2026-24061 A critical argument injection vulnerability (CVE-2026-24061) in GNU InetUtils telnetd allows remote attackers to bypass authentication and achieve root access. The vulnerability occurs because the telnetd service passes the USER environment variable to the system login process without proper sanitization, enabling attackers to inject arguments such as '-f root'.