CuraSec

tag: Saml · 2 items

2026-08-25 · BleepingComputer · source ↗ #wordpress#saml#auth-bypass
  • Engineer — Act: If you run the miniOrange SAML 2.0 SSO plugin on any WordPress site, update it immediately — active exploitation attempts are underway and successful attacks yield unauthenticated admin access via forged SAML responses. Audit recent admin accounts and session logs for signs of unauthorized logins.
  • SOC/IR — Act: Active exploitation is in progress; hunt for anomalous SAML authentication events and unexpected admin account creation or logins on any WordPress instances in your estate, and tune detections for unusual authentication source patterns against WordPress admin endpoints.
  • Leader — Plan: If your organization operates WordPress sites with the miniOrange SAML SSO plugin, direct teams to patch this week — a successful exploit grants full admin takeover, which could expose customer data or be used as a pivot point. Verify your WordPress plugin inventory and patch cadence.
2026-08-25 · The Hacker News · source ↗ #wordpress#saml#privilege-escalation
  • Engineer — Plan: If you run the miniOrange SAML 2.0 SSO WordPress plugin, update it immediately — unauthenticated privilege escalation to admin is high-severity, and active exploitation is claimed by Patchstack, though enrichment signals (EPSS 0.00, no KEV) don’t corroborate it yet.
  • SOC/IR — Learn: No IOCs, ATT&CK mappings, or behavioral TTPs are published; if your estate includes WordPress with SAML SSO, note this as a precursor to watching for unexpected admin account creation, but there is no actionable detection surface today.
  • Leader — Skip
  • Signals: CVE-2026-61979 — CISA KEV: not listed, EPSS 0.00, no public PoC found