CVE-2024-61979Active Exploitation

LOW

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

3.5/ 10 priority

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-24: 1Active Exploitation · 2026-08-24: 1Technical Details · 2026-08-24: 108-24
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets1 URL
Full discourse1 post
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    Attackers are forging SAML responses to bypass WordPress authentication in miniOrange SSO plugin exploits. TRC analysis shows threat actors gained admin access through CVE-2024-61979 and CVE-2024-15981, then escalated privileges within compromised CMS environments. Runtime segmentation helps contain post-compromise lateral movement. #CloudSecurity 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/hackers-target-wordpress-sites-miniorange-auth-bypass-attacks-cve-2026-61979-cve-2026-15981

    Post summary

    The post reports attackers actively exploiting CVE‑2024‑61979 and CVE‑2024‑15981 to gain admin access on WordPress sites via forging SAML responses, highlighting a real‑world containment scenario.

    0000063
    1.9K followersView on X

Explore more