Tag

#Account Takeover

newsCRITICAL 9.1

Auth.js Vulnerability: Homoglyph @ Bypass in Email Normalizer

A critical vulnerability in Auth.js allows an attacker to bypass email validation, potentially leading to account takeover. The flaw affects versions of `next-auth` and `@auth/core` when using the email/magic-link sign-in flow with the default identifier normalizer. Immediate action is required to prevent exploitation.

1 source
newsCRITICAL 9.0

CVE-2026-35198: Critical Stored XSS Vulnerability in HeyForm

A critical stored cross-site scripting (XSS) vulnerability exists in HeyForm, an open-source form builder, prior to version 3.0.0-rc.7. A low-privileged team member can inject malicious JavaScript, leading to account takeover through privilege escalation when a team owner views the form. Update to version 3.0.0-rc.7 or later to mitigate.

1 source
blogHIGH 8.1

Understanding and Defending Against CVE-2026-7655: Privilege Escalation in SureCart Plugin

CVE-2026-7655 is a privilege escalation vulnerability in the SureCart plugin for WordPress, allowing unauthenticated attackers to takeover accounts by manipulating user details via webhook events. This vulnerability has a CVSS score of 8.1 and affects versions up to 4.2.3 of the plugin. Understanding the root cause and attack vector is crucial for defenders to implement effective mitigations.

1 source
newsCRITICAL 9.0

CVE-2026-11374: ManageEngine Products Vulnerable to Predictable SSO Ticket IDs Leading to Account Takeover

A critical vulnerability (CVE-2026-11374, CVSS score of 9) in multiple ManageEngine products allows unauthenticated users to predict SSO ticket IDs, leading to account takeover. Affected products include ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus. Immediate action is required to update vulnerable versions.

1 source