CVE-2026-61979Active Exploitation

HIGHCVSS 8.1 · HIGH

Exploitation observed; activity peaked at 9 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-266

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 9 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 17 mentions across 4 observed days

What's happening

  • Active exploitation reported across 9 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 17 signals
  • Disclosure: 7 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 9 mentions (2026-08-25); latest day: 1
  • 17 total mentions across 4 days

Deep dive

Activity timeline17 mentions / 4d
02579Mentions · 2026-08-24: 3Mentions · 2026-08-25: 9Mentions · 2026-08-26: 4Mentions · 2026-09-02: 1PoC Mentioned / Linked · 2026-08-24: 1Exploit Tool / Code · 2026-08-24: 1Active Exploitation · 2026-08-24: 3Active Exploitation · 2026-08-25: 2Active Exploitation · 2026-08-26: 4Patch / Workaround · 2026-08-24: 2Patch / Workaround · 2026-08-25: 2Patch / Workaround · 2026-08-26: 2Patch / Workaround · 2026-09-02: 1Technical Details · 2026-08-24: 3Technical Details · 2026-08-25: 9Technical Details · 2026-08-26: 4Technical Details · 2026-09-02: 108-2408-2508-2609-02
Signal classification3 categories
Active Exploitation
952.9%
Disclosure
741.2%
General
15.9%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-08-243
Active Exploitation3
2026-08-259
Active Exploitation2Disclosure6General1
2026-08-264
Active Exploitation4
2026-09-021
Disclosure1
Full discourse17 posts
  • Threat Landscape@LandscapeThreat
    Disclosure

    Two critical authentication-bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign-On WordPress plugin enable unauthenticated account takeover, including administrator access. - CVE-2026-61979 allows SAML signature-algorithm confusion, while CVE-2026-15981 incorrectly accepts signatures after OpenSSL errors.

    Post summary

    The tweet announces two critical authentication‑bypass vulnerabilities in the miniOrange SAML 2.0 plugin, detailing SAML signature confusion and improper signature validation, without referencing PoC, exploit tool, patch, or active exploitation.

    01030126
    92 followersView on X
  • Cordoba@cordobahq
    Disclosure

    Attackers are scanning for two CVSS 9.8 auth bypasses (CVE-2026-61979, CVE-2026-15981) in the miniOrange SAML SSO WordPress plugin. Chained, they allow login as any user including admin. All versions up to 5.4.4 affected. Source: The Hacker News

    Post summary

    The text discloses two high-severity auth bypass CVEs (CVSS 9.8) in the miniOrange SAML SSO WordPress plugin, affecting versions up to 5.4.4, and notes attackers are scanning for them, but provides no PoC, exploit code, patch, or confirmed active exploitation details.

    0003061
    5 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    WordPress miniOrange SAML SSO の脆弱性 CVE-2026-61979/15981 が FIX:Admin 権限奪取の恐れ https://iototsecnews.jp/2026/08/25/hackers-exploit-critical-miniorange-saml-sso-flaws-to-hijack-wordpress-admin-accounts/ WordPress miniOrange SAML SSO プラグインにおける、SAML 署名検証の不備を解説する記事です。署名アルゴリズム混同 CVE-2026-61979 や関数戻り値の不適切な型比較 CVE-2026-15981 が背景として存在します。その結果として、認証レスポンス偽造による未認可ログイン/管理者権限の奪取/不正アクセスといった深刻な影響が懸念されます。共有プラグイン・スラッグの仕様上、利用中の製品版で安全更新通知が届かないリスクもあります。影響を受ける最新ビルドへ手動で更新を適用する対応やアクセスログの入念な監視が求められます。 #CVE202615981 #CVE202661979 #miniOrangeSAMLSSO #Vulnerability #WordPress

    Post summary

    The piece announces two critical WordPress miniOrange SAML SSO flaws, explains their technical nature and potential impacts, and recommends updating to the latest build and monitoring access logs for mitigation.

    00010126
    510 followersView on X
  • しーにゃ♪@公式@Syynya
    Active Exploitation

    WordPress向けminiOrange SAML SSOに認証バイパス2件、管理者乗っ取り可能 サイバー攻撃への試行も確認(CVE-2026-15981,CVE-2026-61979) https://rocket-boys.co.jp/security-measures-lab/wordpress-miniorange-saml-sso-auth-bypass-takeover/

    Post summary

    The article reports that two authentication bypass flaws in WordPress miniOrange SAML SSO allow admin takeover, with confirmed real‑world attack attempts for CVE‑2026‑15981 and CVE‑2026‑61979.

    1000077
    911 followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    CVE-2026-61979 and CVE-2026-15981 in miniOrange SAML WordPress plugin allow unauthenticated attackers to log in as admins, DigitalOcean says.

    Post summary

    DigitalOcean reports two CVEs in the miniOrange SAML WordPress plugin that enable unauthenticated attackers to log in as admins.

    1000095
    449 followersView on X
  • DFIR Radar@DFIR_Radar
    Disclosure

    CVE-2026-61979 and CVE-2026-15981, both CVSS 9.8, let unauthenticated attackers forge SAML responses and land in wp-admin on miniOrange SAML plugin installs. #DFIR_Radar https://t.co/mUr3yWdqq8

    Post summary

    The post announces new CVE-2026-61979 and CVE-2026-15981 vulnerabilities with CVSS 9.8, allowing unauthenticated attackers to forge SAML responses and gain wp-admin access on miniOrange SAML plugin installations.

    10000202
    1.9K followersView on X
  • Frontiera Tech@FrontieraTechIT
    Active Exploitation

    🛡️ CYBER BULLETIN | 2026/08/25 🚨 1. CISA adds critical Oracle WebLogic flaw to KEV catalog CISA has listed CVE-2026-21962 (CVSS 10.0) affecting Oracle HTTP Server and WebLogic Server Proxy Plug-in after confirmed active exploitation. Unauthenticated attackers can gain unauthorized access or modify critical data via HTTP. Federal agencies must remediate by August 27. 2. Attackers actively exploiting miniOrange SAML WordPress plugin Two severe authentication bypass flaws (CVE-2026-61979 and CVE-2026-15981) in the popular miniOrange SAML 2.0 SSO plugin allow unauthenticated attackers to log in as any user, including admins. Exploitation attempts are already underway—patch immediately to the fixed versions. 3. Iran-linked hackers shut down UK power plant for four days Hackers affiliated with Iran reportedly disrupted a small-scale UK power generator in July, forcing a four-day outage. While the wider grid was unaffected, the incident highlights growing risks to distributed energy infrastructure from state-linked actors.

    Post summary

    The bulletin reports confirmed active exploitation of Oracle WebLogic flaw CVE-2026-21962 and authentication bypasses in miniOrange SAML plugin, emphasizing immediate patching and remediation.

    1000077
    76 followersView on X
  • Cert-IX@Certix_com
    Active Exploitation

    🚨 ONE ASSERTION BECAME ADMIN CVE-2026-61979 and CVE-2026-15981 are critical authentication bypasses in the miniOrange SAML 2.0 Single Sign On plugin. Both can allow an unauthenticated attacker to forge a SAML assertion and enter WordPress as an existing user—including an administrator. The warning: ⚠️ CVE-2026-61979 exploits signature-algorithm confusion ⚠️ CVE-2026-15981 treats an OpenSSL error return as successful verification ⚠️ Exploitation attempts and opportunistic scanning have been observed Security teams should: ✅ Identify the exact miniOrange edition and version deployed ✅ Upgrade to the patched release listed for that edition ✅ Manually verify updates when WordPress shows no available upgrade ✅ Review administrator sessions from unexpected IP ranges ✅ Reset affected sessions and investigate unauthorised administrative changes One version range cannot describe all seven independently versioned editions. Administrators must use the complete edition-specific remediation matrix. 🚀 Join Cert‑IX Early Access: https://cert-ix.com/early-access 🔎 Complete analysis: https://blog.cert-ix.com/articles/critical-saml-flaws-in-miniorange-a-gateway-for-admin-exploits-mt8hwjlv #miniOrange #SAML #WordPressSecurity #AuthenticationBypass #IdentitySecurity #CVE202661979 #CVE202615981 #CyberExposureManagement #CTEM #CertIX

    Post summary

    MiniOrange SAML plugin has two critical authentication bypass CVEs (CVE‑2026‑61979 and CVE‑2026‑15981) that are already being exploited in the wild. The text urges administrators to verify versions, apply vendor patches, and monitor for unauthorized admin activity.

    0000040
    10 followersView on X
  • SecAlerts@SecAlertsCo
    Active Exploitation

    Threat actors actively target WordPress websites using 2 patched vulns. Info, incl. fix info, now at #SecAlerts: CVE-2026-15981, CVSS 9.8 - https://secalerts.co/vulnerability/CVE-2026-15981 CVE-2026-61979, CVSS 8.1 - https://secalerts.co/vulnerability/CVE-2026-61979 #ciso #cio #cto #vulnerabilities #cybersecurity #msp #mssp https://t.co/h9gG4qgSZc

    Post summary

    The tweet reports that threat actors are actively exploiting two patched WordPress vulnerabilities, with fix information and CVSS scores provided for quick remediation.

    00000141
    881 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Active Exploitation

    WordPress向けminiOrange SAML SSOに認証バイパス2件、管理者乗っ取り可能 サイバー攻撃への試行も確認(CVE-2026-15981,CVE-2026-61979) https://rocket-boys.co.jp/security-measures-lab/wordpress-miniorange-saml-sso-auth-bypass-takeover/ #セキュリティ対策Lab #security #securitynews #セキュリティ #脆弱性

    Post summary

    The tweet confirms that CVE-2026-15981 and CVE-2026-61979 enable authentication bypass and potential admin takeover, with evidence of active exploitation attempts in the wild.

    00000188
    554 followersView on X
  • CVETodo@CveTodo
    Active Exploitation

    Threat actors are actively targeting WordPress websites through two critical authentication bypass vulnerabilities — CVE-2026-61979 and CVE-2026-15981 — in the MiniOrange SAML 2. https://cvetodo.com/news/miniorange-wordpress-saml-plugin-under-active-attack-as-silent-patches-leave-admins-exposed #WordPress #miniOrange #AuthBypass #CVE #InfoSec https://t.co/WxFabKGmpW

    Post summary

    Threat actors are actively exploiting two authentication bypass CVEs in the MiniOrange WordPress SAML plugin, though no PoC, patch, or exploitation tool is provided.

    0000036
    19 followersView on X
  • Shah Sheikh@shah_sheikh
    Disclosure

    WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities: CVE-2026-61979 and CVE-2026-15981 are authentication bypass vulnerabilities affecting the MiniOrange SAML 2.0 SSO plugin. The post WordPress Websites Targeted via MiniOrange Plugin… https://www.securityweek.com/wordpress-websites-targeted-via-miniorange-plugin-vulnerabilities/?utm_source=dlvr.it&utm_medium=twitter https://t.co/ZfQ1wLOyqk

    Post summary

    The post announces two authentication‑bypass vulnerabilities (CVE-2026-61979 & CVE-2026-15981) in the MiniOrange SAML 2.0 SSO plugin affecting WordPress sites, without providing PoC or exploit details.

    0000051
    2.3K followersView on X
  • CyberNewsDaily@NewsDaily18579
    General

    🟠 miniOrange SAML plugin flaw lets attackers sign in as any WordPress user, including admins. CVE-2026-61979 (CVSS: 8.1/10) [EPSS: 0.3%] is the key. via The Hacker News #WordPress #Cybersecurity https://t.co/oi6Isx28ZZ

    Post summary

    The tweet announces a vulnerability in the miniOrange SAML plugin (CVE‑2026‑61979) that allows attackers to authenticate as any WordPress user, but it provides no PoC, exploit details, active exploitation evidence, or patch information.

    0000035
    22 followersView on X
  • The Daily Tech Feed@dailytechonx
    Disclosure

    New critical vulnerabilities in the miniOrange SAML 2.0 plugin are letting attackers bypass authentication and log in as WordPress admins. CVE-2026-61979 and CVE-2026-15981 involve signature algorithm flaws and malformed signature errors in OpenSSL. Owners running pre-17.0.6 versions are at serious risk—update immediately to secure admin access and prevent chain exploits. #WordPress #SAML #miniOrange #Vulnerability #Cybersecurity #EditionsPatch https://thedailytechfeed.com/critical-miniorange-saml-bugs-let-attackers-become-wordpress-admins/

    Post summary

    MiniOrange SAML 2.0 plugin contains two critical CVEs (CVE-2026-61979, CVE-2026-15981) that exploit OpenSSL signature flaws, allowing attackers to bypass authentication and gain admin access. Users on versions prior to 17.0.6 are urged to update immediately.

    0000066
    664 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    Attackers are forging SAML responses to bypass WordPress authentication in miniOrange SSO plugin exploits. TRC analysis shows threat actors gained admin access through CVE-2024-61979 and CVE-2024-15981, then escalated privileges within compromised CMS environments. Runtime segmentation helps contain post-compromise lateral movement. #CloudSecurity 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/hackers-target-wordpress-sites-miniorange-auth-bypass-attacks-cve-2026-61979-cve-2026-15981

    Post summary

    Attackers are actively exploiting CVE-2024-61979 and CVE-2024-15981 to forge SAML responses, bypass WordPress authentication and gain administrative privileges within miniOrange‑enabled sites.

    0000063
    1.9K followersView on X
  • CyberAlertsHQ@CyberAlertsHQ
    Active Exploitation

    🚨 WORDPRESS ACTIVE EXPLOITATION ALERT: Hackers are targeting WordPress sites using TWO critical vulnerabilities in the miniOrange SAML SSO plugin. CVE-2026-61979 + CVE-2026-15981 Attackers can chain the flaws to: 🔓 Bypass authentication 🎭 Forge trusted SAML responses 🍪 Obtain administrator sessions 👑 Log into WordPress as an ADMIN ⚠️ Active exploitation attempts and opportunistic scanning have been detected. A public PoC exploit is also available—meaning attack activity could accelerate. WordPress administrators using miniOrange SAML SSO should verify their version and update immediately. https://www.bleepingcomputer.com/news/security/hackers-target-wordpress-sites-in-miniorange-auth-bypass-attacks/

    Post summary

    The post reports that attackers are actively exploiting two critical CVEs in the miniOrange SAML SSO plugin, with a public PoC available and a call for immediate patching.

    0000072
    113 followersView on X
  • SecureChap@SecureChap
    Active Exploitation

    The miniOrange SAML 2.0 SSO plugin for WordPress accepted attacker-controlled HMAC signatures when an RSA key was configured. CVE-2026-61979 let an attacker supply HMAC-SHA1 in a SAML response and have the plugin treat the IdP's RSA public key as the HMAC secret. CVE-2026-15981 then accepted an OpenSSL verification return code of -1 as success on the resulting malformed signature. The two flaws chained to produce a forged assertion that yielded an admin session cookie. Attacks hit version 16.1.9 of the Standard edition on 16 August 2026. Patches exist for every tier: free single-site reaches 5.4.5, premium single-site reaches 13.0.4, and VIP multisite reaches 35.0.7. The code read the signature algorithm from the incoming response instead of enforcing the value stored for the configured IdP.

    Post summary

    The CVEs in the miniOrange SAML 2.0 plugin were actively exploited to forge SAML assertions and obtain admin sessions, but patches are available for all supported tiers.

    0000062
    165 followersView on X

Explore more