Tag
critical
advisory
IBM WebSphere Application Server Authentication Bypass Vulnerability (CVE-2026-16184)
5 TTPs 7 CVEs 5 IOCsA remote attacker can bypass authentication in IBM WebSphere Application Server versions 9.0 and 8.5 by sending a crafted unauthenticated request, potentially leading to unauthorized access and impact on confidentiality, integrity, and availability.
WebSphere Application Server 9.0 +8
vulnerability
authentication-bypass
websphere
broken-access-control
privilege-escalation
deserialization
RCE
server-side-request-forgery
+6
5t
7c
5i
high
advisory
HAProxy CVE-2021-40346 Integer Overflow Leading to HTTP Request Smuggling and ACL Bypass
2 TTPs 1 CVEA critical integer overflow vulnerability, CVE-2021-40346, in HAProxy's `htx_add_header()` function allows unauthenticated attackers to bypass access control rules by crafting HTTP requests with specific header name lengths, leading to HTTP request smuggling and unauthorized access to backend paths, for which a public exploit is available.
HAProxy +4
integer-overflow
http-smuggling
acl-bypass
webserver
2t
1c