All recent CVEs
| CVE | CVSS | Severity | Product | Summary | Published |
|---|---|---|---|---|---|
| CVE-2026-5343 | 7.4 | high | saml sso - service provider | Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal SAML SSO - Service Provider allows Pri | 135d ago |
1 CVEs published in the last four months and 3 stories. Exploited flaws first.
| CVE | CVSS | Severity | Product | Summary | Published |
|---|---|---|---|---|---|
| CVE-2026-5343 | 7.4 | high | saml sso - service provider | Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal SAML SSO - Service Provider allows Pri | 135d ago |

Two critical authentication bypass vulnerabilities, both rated CVSS 9.8, in the miniOrange SAML 2.0 Single Sign On WordPress plugin were actively exploited before public vulnerability databases accurately reflected the affected paid editions. These flaws, identified as CVE-2026-61979 and CVE-2026-15981, allowed unauthenticated attackers to forge SAML authentication responses and gain…

Reports indicate that WordPress websites are currently being targeted through the exploitation of two authentication bypass vulnerabilities found in the MiniOrange SAML 2.0 SSO plugin. These vulnerabilities have been assigned the identifiers CVE-2026-61979 and CVE-2026-15981. The active targeting suggests that attackers are leveraging these flaws to gain unauthorized access to affected…

Threat actors are actively attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. These vulnerabilities, tracked as CVE-2026-61979 and CVE-2026-15981, can be chained together to forge SAML responses and gain administrative access to affected WordPress sites.