Storyline
Critical Authentication Vulnerabilities in Enterprise Infrastructure
Multiple critical authentication bypass and credential exposure vulnerabilities have been discovered across enterprise infrastructure components, including 24,000+ internet-exposed BMCs leaking password hashes via a 20-year-old IPMI flaw, critical VMware vCenter authentication bypass flaws, and an actively exploited Check Point Security Management Server vulnerability. These exposures create significant risks for unauthorized server access and data center compromise.
This is a long-running storyline that has developed over 8 days. The homepage highlights its most recent activity, so the outlet count there reflects the latest wave. The totals above cover the full run.
Baseboard Management Controller (BMC)IPMI protocolVMware vCenterCheck Point Security Management ServerInternet-exposed servers