Broken Access Control is a vulnerability tracked by ThreatCluster, appearing in 3 threat clusters built from 4 intelligence report mentions.
Broken Access Control is a vulnerability tracked across 3 threat clusters and 4 intelligence report mentions on ThreatCluster. First observed February 24, 2026; most recent activity July 24, 2026.
The Secure Login (2FA) plugin for Atlassian Jira, Confluence, and Bitbucket has a serious broken access control vulnerability. This flaw allows attackers with valid user credentials to bypass multi-factor authentication…
The Click To Pray app, endorsed by the Pope, has leaked over 700,000 users' personal information due to an Insecure Direct Object Reference (IDOR) vulnerability. Discovered by ethical hacker BobDaHacker in January 2026,…
SolarWinds has issued security updates for four critical remote code execution vulnerabilities in its Serv-U software, which could allow attackers to gain root access to unpatched servers. The affected software is used…
Broken Access Control is a vulnerability tracked by ThreatCluster, appearing in 3 threat clusters built from 4 intelligence report mentions.
The most recent intelligence report mentioning Broken Access Control on ThreatCluster is dated July 24, 2026. Activity was first observed February 24, 2026, giving a tracked span from then to July 24, 2026.
Across ThreatCluster reporting, Broken Access Control most frequently co-occurs with Data Breach, Phishing, La Machi Communication, Pope's Worldwide Prayer Network, CVE-2025-40538, among 12 tracked related entities.
The most significant recent cluster is “Critical Vulnerability in syracom AG 2FA Plugin for Atlassian Products” (3 articles · Updated June 17, 2026). Broken Access Control appears across 3 threat clusters in total, listed above with sources.
Broken Access Control appears in 4 intelligence report mentions across 3 deduplicated threat clusters, aggregated from 17,000+ monitored sources.