Four suppliers, 15 CVE, identity proxy stack subjected to coordinated attack
2026-10-05 23:57:26
CoinMeta data: According to Forkast, from October 2nd to 5th, 2026, the identity proxy stack suffered a coordinated attack, resulting in four vulnerabilities at the identity layer that led to a concentrated failure in security. The Zitadel incident involved 10 vulnerabilities; CVE-2026-105215 allowed unauthorized accounts to hijack identities in advance; CVE-2026-105209 enabled attackers to register authenticators across different organizations; CVE-2026-105211 permitted MFA to bypass security measures; the Zimbra vulnerability ( CVE-2026-73570 ) allowed attackers to obtain encrypted trust roots through unauthorized command injection; the CVE-2026-73570 vulnerability ( CVE-2026-71885 ) enabled attackers to impersonate any participant; the MCP OAuth credential theft was related to Anthropic MCP Python SDK; when malicious servers returned a 404 error, SDK allowed attackers to bypass verification and directly obtain configurations. Defects in the verification logic of various systems led to the disruption of identity integration.
Bullish 0
Bearish 0
Source:Forkast
This content is for market information only and does not constitute investment advice.