CVE-2026-62916
Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a
CVSS
9.1
Critical
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Sep 3, 2026 · Last modified: Sep 3, 2026 · CWE-288
Not enough EPSS history yet.
Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-847777.4 HIG—
———Unauthenticated Broken Authentication in Really Simple SSL <= 9.8.0 versions.15hCVE-2026-811683.7 LOW—
——0Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue affects CAPTCHA Protected Page versions: from 0.0.0 to 1.0.2.2dCVE-2026-16647——
——0Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass. This issue affects Disable Login Page versions: from 0.0.0 to 1.1.4.2dCVE-2026-822257.4 HIG14.9%
——4Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 versions.3dCVE-2026-822698.1 HIG22.6%
——7Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middleware. Attackers with valid API keys can bypass these security controls and retain full API access even when their account is locked or password change is required.6dCVE-2026-769439.8 CRI49.7%
——15Xiiaozet LK100Wt contains an authentication weakness within an
administrative service that may allow an attacker to bypass intended
access controls and obtain command execution capabilities. Successful
exploitation could allow unauthorized interaction with privileged
functionality and may lead to complete device compromise.15h