Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Authentication bypass and Patch Tuesday: what do teams need to fix first?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 17031
Topic starter  

TL;DR: Microsoft’s May 2026 Patch Tuesday covers 137 CVEs with no zero days, while Expel highlights high-priority RDS, SharePoint, and DNS Client issues plus Fortinet authentication bypass flaws that attackers are actively automating. The pattern is familiar: exposed management surfaces, stale vulnerabilities, and privileged access paths remain a reliable route to compromise.

NHIMG editorial — based on content published by Expel: May 2026 Patch Tuesday analysis and authentication bypass findings

By the numbers:

  • Microsoft’s May 2026 Patch Tuesday addresses 137 CVEs and includes 16 classified as critical.
  • CVE-2026-35616 carries a CVSS score of 9.1 because it bypasses API authentication and can execute arbitrary commands on FortiClient EMS endpoints.
  • Microsoft rates CVE-2026-41096 at CVSS 9.8, even while labelling exploitation unlikely.

Questions worth separating out

Q: What breaks when a security management interface has an authentication bypass?

A: When a security management interface bypasses authentication, attackers may reach the control layer that configures enforcement, policy, and access decisions.

Q: When should teams prioritise an older CVE over newer patch work?

A: Prioritise the older CVE when it is externally reachable, has proof of concept code, and affects a privileged management surface or identity control path.

Q: What do security teams get wrong about severity-based patching?

A: They often assume a high score means equal urgency everywhere.

Practitioner guidance

  • Remove direct internet exposure from management surfaces Place VPN, firewall, and appliance consoles behind restricted administrative networks, jump hosts, or strong conditional access so authentication bypasses cannot be reached from the public internet.
  • Review super-admin and REST API account creation paths Audit every device and platform that can create high-privilege users or API accounts, then alert on new administrative identities, policy edits, and logging changes.
  • Treat old bypass CVEs as active risk Prioritise remediation for publicly exploited authentication bypass flaws even when they are older than the latest Patch Tuesday cycle, especially on exposed appliances and edge systems.

What's in the full article

Expel's full analysis covers the operational detail this post intentionally leaves for the source:

  • Device-level exploitation notes for the specific Windows and Fortinet CVEs discussed in the patch roundup
  • The incident timeline showing how the FortiGate compromise progressed from bypass to super-admin control
  • The response details that explain how segmentation contained the attack and where detection occurred
  • The practical patching and exposure-management recommendations Expel applies to internet-facing management systems

👉 Read Expel’s May 2026 Patch Tuesday analysis and Fortinet bypass findings →

Authentication bypass and Patch Tuesday: what do teams need to fix first?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 16618
 

Authentication bypass is an identity control failure, not just a software flaw. When a management interface accepts traffic without properly verifying the caller, the security boundary collapses before IAM or PAM can enforce role, session, or audit controls. That is why bypass vulnerabilities belong in the same governance conversation as privileged access and service account exposure. Practitioners should treat exposed admin surfaces as identity gateways, not generic endpoints.

A few things that frame the scale:

  • 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, according to 2024 ESG Report: Managing Non-Human Identities.
  • Two-thirds of enterprises have endured a successful cyberattack resulting from compromised non-human identities, with a quarter encountering multiple attacks.

A question worth separating out:

Q: Who is accountable when privileged management access is used to disrupt endpoints?

A: Accountability sits with the organisation that granted and governed the privileged access, not just the attacker who abused it. IAM, PAM, endpoint engineering, and security operations all share responsibility for role scope, session trust, and command gating. Frameworks such as NIST CSF and OWASP NHI are relevant because they connect access governance to operational resilience.

👉 Read our full editorial: Patch Tuesday and authentication bypass risk: why old CVEs still matter



   
ReplyQuote
Share: