Authentication bypass vulnerabilities
Authentication bypass lets an attacker reach protected functionality without valid credentials — broken login checks, forgeable tokens, or alternate paths that skip the check entirely. On edge devices such as VPNs and firewalls, an auth bypass is often equivalent to full compromise and is frequently chained with a post-auth RCE.
Classification is assigned by the CSIRTS enrichment pipeline from the advisory text. The list below shows the latest advisories tagged authentication bypass, newest first, across national CERTs, vendor PSIRTs and vulnerability databases — exploited marks CVEs in the CISA KEV catalog.
Latest authentication bypass advisories
[UPDATE] [mittel] Golang Go-Module (Net, Image, Crypto: Mehrere Schwachstellen
[UPDATE] [hoch] Golang Go: Mehrere Schwachstellen
[UPDATE] [hoch] Golang Go: Mehrere Schwachstellen
[UPDATE] [hoch] Keycloak: Mehrere Schwachstellen
[UPDATE] [hoch] Mozilla Firefox, Firefox ESR und Thunderbird: Mehrere Schwachstellen
[UPDATE] [mittel] Golang Go: Mehrere Schwachstellen
[UPDATE] [hoch] Redis: Mehrere Schwachstellen
[UPDATE] [hoch] IBM License Metric Tool: Mehrere Schwachstellen
[UPDATE] [hoch] IBM QRadar SIEM: Mehrere Schwachstellen
[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff
[UPDATE] [hoch] Red Hat Enterprise Linux (nodejs:24): Mehrere Schwachstellen
[UPDATE] [mittel] Node.js: Mehrere Schwachstellen
[UPDATE] [hoch] Erlang/OTP: Mehrere Schwachstellen
[UPDATE] [hoch] libssh: Mehrere Schwachstellen
[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff
[UPDATE] [mittel] Red Hat OpenShift Container Platform (protobufjs, fast-uri): Mehrere Schwachstellen
[UPDATE] [hoch] Apache HTTP Server: Mehrere Schwachstellen
[UPDATE] [mittel] GNU tar: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
[UPDATE] [hoch] Dell Secure Connect Gateway: Mehrere Schwachstellen
CVE-2026-74994: inets, httpd: Authentication Bypass via Directory Namespace Collapse in httpd mod_auth
CVE-2026-73270: httpd mod_auth directory protection bypassed by request path casing on case-insensitive filesystems
CVE-2026-66835: httpd mod_auth directory protection bypassed by a doubled slash in the request path
[UPDATE] [mittel] ILIAS: Mehrere Schwachstellen
[UPDATE] [hoch] Google Chrome: Mehrere Schwachstellen
[UPDATE] [hoch] Mozilla Firefox und Thunderbird: Mehrere Schwachstellen
[UPDATE] [hoch] Mozilla Firefox und Thunderbird: Mehrere Schwachstellen
[UPDATE] [hoch] PostgreSQL: Mehrere Schwachstellen
[UPDATE] [kritisch] Citrix Systems NetScaler (Gateway und ADC): Mehrere Schwachstellen
[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen
[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen
[UPDATE] [hoch] MISP: Mehrere Schwachstellen
[UPDATE] [hoch] IBM i: Mehrere Schwachstellen
[UPDATE] [mittel] cURL: Mehrere Schwachstellen
[UPDATE] [mittel] IBM i: Mehrere Schwachstellen
[UPDATE] [hoch] Langflow OSS: Mehrere Schwachstellen
[UPDATE] [mittel] Grafana: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen und Manipulation von Dateien
[UPDATE] [hoch] MongoDB Clients: Mehrere Schwachstellen
[UPDATE] [hoch] Composer: Mehrere Schwachstellen
[UPDATE] [mittel] Apache HttpComponents: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
[UPDATE] [mittel] Checkmk: Mehrere Schwachstellen ermöglichen Umgehen von Sicherheitsvorkehrungen
[UPDATE] [hoch] Internet Systems Consortium BIND: Mehrere Schwachstellen
[UPDATE] [hoch] Snipe-IT: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
[UPDATE] [mittel] Grafana Enterprise: Mehrere Schwachstellen ermöglichen Erlangen von Benutzer- oder Administratorrechten
PALLET CONTROL products vulnerable to improper access control
NCSC-2026-0341 [1.00] [M/H] Kwetsbaarheden verholpen in Google Chrome
[NEU] [hoch] Microsoft Clouddienste: Mehrere Schwachstellen
[NEU] [mittel] Dell integrated Dell Remote Access Controller: Schwachstelle ermöglicht Codeausführung
[NEU] [hoch] SEPPmail Secure E-Mail Gateway: Mehrere Schwachstellen
[UPDATE] [hoch] Golang Go: Mehrere Schwachstellen
Other vulnerability classes
New authentication bypass advisories, in your inbox. The daily briefing covers every advisory in this class the morning after it lands. Subscribe free — one email every morning after 06:00 UTC, one-click unsubscribe. Tracking specific products instead? Watch them from any product page and get alerted only when they ship a new advisory.