Vulnerability Feed
Vulnerabilities affecting IAM products — directory services, federation, MFA, SSO, and PAM platforms
Recent Identity-Related CVEs
CVE-2026-31847 — FortiAuthenticator RCE
Unauthenticated remote code execution via crafted RADIUS authentication packet.
CVE-2026-28391 — Okta OIDC Token Bypass
Token validation flaw allows authentication bypass in specific OIDC flow configurations.
CVE-2026-29104 — PingFederate XXE
XML External Entity injection in SAML metadata parser allows SSRF.
CVE-2026-30582 — Azure AD B2C Policy Injection
Custom policy XML injection allows privilege escalation in B2C tenants.
CVE-2026-31205 — Keycloak Session Fixation
Session token not rotated after authentication in specific broker flows.