Actively exploited miniOrange SAML bypasses (CVE-2026-15981, CVE-2026-61979) forge admin logins the IdP never saw and version scanners called patched.