CVE-2026-22049
ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to th
CVSS
8.8
Alto
EPSS
0.3%
p21
KEV
—
Exploit Today
6
0-100
Publicado: 22 jul 2026 · Última mod.: 20 ago 2026 · CWE-288
0.3%EPSS · 30 días0.3%
2026-08-092026-09-05
ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could allow an attacker with valid credentials to bypass MFA.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-761697.5 ALT42.7%
——13fastify versions >= 4.0.0 and before 5.12.2 can route a malformed URL sent under one plugin prefix to the custom not-found handler of a different sibling plugin, and invoke it without the preHandler hook declared for that handler. The internal not-found router for encapsulated handlers dispatches malformed paths through a single shared handler pointer before URL decoding, ignoring the prefix and skipping the selected handler's normal lifecycle. An unauthenticated attacker can therefore reach an authentication-protected private fallback through an unrelated public prefix and read its full response, bypassing the authentication hook and breaking prefix encapsulation. Users should upgrade to fastify 5.12.2 or later.3dCVE-2026-629169.1 CRÍ45.4%
——14Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.2dCVE-2026-847777.4 ALT14.9%
——4Unauthenticated Broken Authentication in Really Simple SSL <= 9.8.0 versions.4dCVE-2026-811683.7 BAJ26.3%
——8Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue affects CAPTCHA Protected Page versions: from 0.0.0 to 1.0.2.5dCVE-2026-166474.1 MED20.5%
——6Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass. This issue affects Disable Login Page versions: from 0.0.0 to 1.1.4.3dCVE-2026-822257.4 ALT14.9%
——4Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 versions.5d