Ping-identity
26 CVEs tracked since 2022. Since Apr 2022, none of them reached CISA KEV.
Ping-identity CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2022-04 | 4 | 0 |
| 2022-05 | null or fewer | |
| 2022-06 | 6 | 0 |
| 2022-07 | null or fewer | |
| 2022-08 | null or fewer | |
| 2022-09 | null or fewer | |
| 2022-10 | null or fewer | |
| 2022-11 | null or fewer | |
| 2022-12 | null or fewer | |
| 2023-01 | null or fewer | |
| 2023-02 | null or fewer | |
| 2023-03 | null or fewer | |
| 2023-04 | 6 | 0 |
| 2023-05 | null or fewer | |
| 2023-06 | null or fewer | |
| 2023-07 | null or fewer | |
| 2023-08 | null or fewer | |
| 2023-09 | null or fewer | |
| 2023-10 | 5 | 0 |
| 2023-11 | null or fewer | |
| 2023-12 | null or fewer | |
| 2024-01 | null or fewer | |
| 2024-02 | null or fewer | |
| 2024-03 | null or fewer | |
| 2024-04 | null or fewer | |
| 2024-05 | null or fewer | |
| 2024-06 | null or fewer | |
| 2024-07 | 5 | 0 |
Products
The products that kept showing up in Ping-identity's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Ping-identity.
- CVE-2026-21391Improper Claim Validation in PingAM OIDC Provider—
- CVE-2026-20773Improper Authorization in PingFederate Administrative Expression Evaluation Endpoint—
- CVE-2025-32736PingFederate Administrative Console CSRF weaknesses—
- CVE-2026-20746PingDirectory copying of virtual attributes leads to memory exhaustion—
- CVE-2025-20628Insufficient granularity of access control for Remote Connector Servers in client mode—
- CVE-2025-27935Authentication Bypass in OTP (One-time Passcode) IdP Adapter Integration Kit—
- CVE-2025-26862PingFederate unexpected browser flow initiation in redirectless mode—
- CVE-2024-25573Stored Cross-Site Scripting in Administrative Console Context—
- CVE-2025-22854Possible thread exhaustion from processing http responses in PingFederate Google Adapter—
- CVE-2025-21085PingFederate OAuth Grant attribute duplication may use excessive memory—
- CVE-2025-20059PingAM Java Policy Agent path traversal9.1
- CVE-2024-23983Access rules for PingAccess may be circumvented with URL-encoded characters—
- CVE-2024-25566Open Redirect in PingAM6.1
- CVE-2024-23600PingIDM Query Filter Vulnerability2.7
- CVE-2024-21832PingFederate REST API Data Store Injection3.5
The record
- Peak rank
- #113 in Apr 2023
- Busiest month shown
- Jun 2022, 6 CVEs
- Months with a KEV entry
- 0 since Apr 2022
- Monthly snapshots
- 5 since 2022