Cwe-306 - Missing Authentication For Critical Function is a cwe tracked across 14 threat clusters and 17 intelligence report mentions on ThreatCluster. First observed April 24, 2026; most recent activity July 10, 2026.
Cisco has disclosed a critical authentication bypass vulnerability, CVE-2026-20182, affecting its Catalyst SD-WAN Controller and Manager. This flaw allows unauthenticated remote attackers to bypass authentication and…
AHA! disclosed three critical vulnerabilities in Yarbo robot firmware v2.3.9, identified as CVE-2026-7413, CVE-2026-7414, and CVE-2026-7415. The vulnerabilities include a hidden backdoor, hardcoded credentials, and an…
A critical zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft has been exploited by the ShinyHunters group, leading to breaches of over 100 organizations, primarily in the education sector. The vulnerability…
pgAdmin 4 version 9.16 was released to patch seven vulnerabilities, including critical issues tracked as CVE-2026-12044 to CVE-2026-12050. These vulnerabilities could allow attackers to execute arbitrary commands, gain…
On November 18, 2024, Palo Alto Networks disclosed two critical vulnerabilities in PAN-OS: CVE-2024-0012 and CVE-2024-9474. CVE-2024-0012 is an authentication bypass vulnerability that allows unauthenticated attackers…
The Aqara IAM/SSO gateway (gw-builder.aqara.com) has a critical vulnerability (CVE-2026-50086) that allows unauthorized access to cryptographic operations involving the platform's signing key. This flaw enables…
Oracle released its first Critical Security Patch Update (CSPU) on May 28, 2026, addressing 35 vulnerabilities across multiple product families, including Oracle Database, Oracle REST Data Services, and Oracle…
JetBrains has issued patches for critical vulnerabilities in JetBrains Hub that could lead to full authentication bypass, account takeover, and privilege escalation. The vulnerabilities, tracked as CVE-2026-56141,…
Apache OFBiz has critical vulnerabilities that allow attackers to exploit hardcoded keys and bypass authentication. The vulnerabilities, CVE-2026-31986 and CVE-2026-45434, were published on 2026-05-19 and affect all…
Seagull Software's BarTender has two critical vulnerabilities affecting versions 2010, 2016, 2019, and 2021. CVE-2026-25550 allows unauthenticated remote code execution via the .NET Remoting service on TCP port 7375,…