A security industry blog post traces SAML's origins as a 2002 OASIS committee standard built on XML, arguing it powered the early single sign-on industry but has since become overly complex and fragile. The piece, citing security researcher Thomas Ptacek, contends SAML's reliance on XML signature validation makes real-world implementations difficult to secure, and calls for organizations to move to newer alternatives like OpenID Connect (OIDC).
blog.trailofbits.com
· 2026-09-22
Security researchers at Previdian and Belgium's national cyber center report that hackers are actively probing a critical authentication-bypass vulnerability in Citrix NetScaler appliances, tracked as CVE-2026-19490. The flaw affects NetScaler devices configured as AAA virtual servers or Gateways, and exploitation attempts began after a working proof-of-concept was posted online. Citrix patched the issue in mid-August but had not confirmed active exploitation as of its most recent advisory.
bleepingcomputer.com
· 2026-09-04
Security researchers say hackers are exploiting two chained vulnerabilities, CVE-2026-61979 and CVE-2026-15981, in the miniOrange SAML 2.0 Single Sign On plugin to forge SAML responses and log into WordPress sites as administrators. The plugin, made by Xecurify, lets sites authenticate through identity providers like Microsoft Entra ID, Okta, Google Workspace or OneLogin, and comes in a free version plus six paid editions used by roughly 30,000 customers.
bleepingcomputer.com
· 2026-08-24