Threat Landscape[verified]@LandscapeThreatDisclosure
The tweet announces two critical authentication‑bypass vulnerabilities in the miniOrange SAML 2.0 plugin, detailing SAML signature confusion and improper signature validation, without referencing PoC, exploit tool, patch, or active exploitation.
ThreatCluster[verified]@threatclusterDisclosure
DigitalOcean reports two CVEs in the miniOrange SAML WordPress plugin that enable unauthenticated attackers to log in as admins.
DFIR Radar[verified]@DFIR_RadarDisclosure
The post announces new CVE-2026-61979 and CVE-2026-15981 vulnerabilities with CVSS 9.8, allowing unauthenticated attackers to forge SAML responses and gain wp-admin access on miniOrange SAML plugin installations.
Frontiera Tech[verified]@FrontieraTechITActive Exploitation
The bulletin reports confirmed active exploitation of Oracle WebLogic flaw CVE-2026-21962 and authentication bypasses in miniOrange SAML plugin, emphasizing immediate patching and remediation.
Cert-IX[verified]@Certix_comActive Exploitation
MiniOrange SAML plugin has two critical authentication bypass CVEs (CVE‑2026‑61979 and CVE‑2026‑15981) that are already being exploited in the wild. The text urges administrators to verify versions, apply vendor patches, and monitor for unauthorized admin activity.
セキュリティ対策Lab[verified]@securityLab_jpActive Exploitation
The tweet confirms that CVE-2026-15981 and CVE-2026-61979 enable authentication bypass and potential admin takeover, with evidence of active exploitation attempts in the wild.
Shah Sheikh[verified]@shah_sheikhDisclosure
The post announces two authentication‑bypass vulnerabilities (CVE-2026-61979 & CVE-2026-15981) in the MiniOrange SAML 2.0 SSO plugin affecting WordPress sites, without providing PoC or exploit details.
The Daily Tech Feed[verified]@dailytechonxDisclosure
MiniOrange SAML 2.0 plugin contains two critical CVEs (CVE-2026-61979, CVE-2026-15981) that exploit OpenSSL signature flaws, allowing attackers to bypass authentication and gain admin access. Users on versions prior to 17.0.6 are urged to update immediately.