Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: identity (5 articles)Clear

FreeIPA flaw chain lets anonymous clients grant themselves admin credentials

Red Hat disclosed a flaw chain in FreeIPA, the identity-management system that controls logins across Linux domains, that lets a client which never authenticated create an administrator account for itself. The FreeIPA flaw, CVE-2026-76578 and rated 9.8, is an access rule that lets anyone write a one-time-password token without logging in, and does not restrict what else is written alongside it. The second flaw, CVE-2026-76560 in the underlying 389 Directory Server, treats an unauthenticated client's empty name as matching an empty ownership field, so it passes an owner-only check by being nobody. Together they let an anonymous client write a Kerberos identity into the administrators group; a default install is affected.

Check
Apply Red Hat's updates for FreeIPA and 389 Directory Server as soon as available, and audit your directory for unexpected Kerberos identities and accounts recently added to the administrators group.
Affected
Organizations running FreeIPA or Red Hat Identity Management (CVE-2026-76578, CVE-2026-76560); an unauthenticated client can create an admin-level Kerberos identity, and a default install is vulnerable, putting the whole identity system at risk.
Fix
Patch FreeIPA and the directory server promptly, restrict who can reach the directory service over the network, hunt for rogue tokens and admin accounts, and rotate credentials if abuse is found.

Critical Keycloak flaw lets attackers take over any account via password reset

A critical flaw in Keycloak, the widely used open-source identity and access management server, lets an unauthenticated attacker take over any account through its password-reset flow. Tracked as CVE-2026-18963, the bug is improper state validation in the reset-credentials flow: a crafted request to the reset endpoint pushes the authentication session straight to the password-update step, so the action token Keycloak normally emails is never required, and the attacker sets new credentials for a chosen user. It needs no user interaction and works against any account, including administrators. Red Hat fixed it in Keycloak 26.7.2 and related releases; there is no confirmed exploitation yet.

Check
Upgrade Keycloak to a fixed release such as 26.7.2, and if you ran a vulnerable version, revoke active and offline sessions and rotate client secrets, since tokens may already have been issued.
Affected
Organizations running Keycloak with the forgotten-password feature enabled on a vulnerable version (CVE-2026-18963); an unauthenticated attacker can reset and take over any user or admin account without the email verification step.
Fix
Patch promptly, then treat exposure as possible account compromise: revoke sessions, rotate accessible client secrets, review identity links and admin permissions, and remember downstream services may hold tokens issued before patching.

Exploited Entra ID flaw scored a perfect ten but was fixed in Microsoft's cloud

Microsoft disclosed that a critical flaw in Entra ID, its cloud identity and access service formerly known as Azure Active Directory, was exploited in the wild, though it says the issue is fully mitigated on its side and customers need take no action. Tracked as CVE-2026-69836 and scored 10.0, it is an unsafe-deserialization bug that let an unauthenticated attacker run code over the network in the identity service. Because Entra ID underpins sign-in to Microsoft 365, Azure, and many third-party apps, a code execution flaw there is unusually serious. Microsoft has not shared how it was exploited, so the practical step is reviewing identity logs for suspicious activity before the disclosure.

Check
No patching is required since Microsoft fixed this in its cloud, but review Entra ID sign-in and audit logs for suspicious service-principal changes, role assignments, and unusual token or admin activity.
Affected
Organizations relying on Microsoft Entra ID for identity (CVE-2026-69836); the flaw allowed unauthenticated remote code execution in the identity service itself, though Microsoft states it is now fully mitigated.
Fix
Treat this as a prompt to hunt for identity compromise, not to patch: review privileged accounts, tokens, and app registrations for anomalies, tighten conditional access, and monitor Entra logs.

Identity governance vendor SailPoint discloses GitHub repository breach - third-party app flaw to blame

SailPoint, the identity governance vendor used by many large enterprises, disclosed in a SEC 8-K filing that attackers gained unauthorized access to a subset of its GitHub repositories on April 20. The company's incident response team contained the intrusion the same day. SailPoint says no customer data in production or staging was accessed and its services were not interrupted. The root cause was a vulnerability in a third-party application, which has been remediated. SailPoint notified affected customers directly and says no further customer action is needed. The company has not disclosed what data was actually in the impacted repos.

Check
If you use SailPoint (IdentityNow, IdentityIQ, or related products), check whether you received a direct notification dated after April 20, 2026, and review the scope details in your account portal.
Affected
SailPoint customers who received a direct breach notification dated on or after April 20, 2026. The company has not publicly disclosed which products, repositories, or customer subsets were specifically named in the notifications. No customer data in production or staging environments was accessed per SailPoint's SEC filing.
Fix
Follow guidance in your direct SailPoint notification. As a precaution, rotate any API tokens or service-account credentials issued for SailPoint integration over the past 12 months. Review SailPoint integration audit logs for unexpected activity from April onward. Ask SailPoint for the name of the third-party application whose flaw caused the intrusion - your organization may use it elsewhere.

Cisco Webex SSO flaw lets unauthenticated attackers impersonate any user (CVE-2026-20184) - four critical bugs patched this week

Cisco has patched four critical vulnerabilities this week across Webex and Identity Services Engine (ISE). The standout flaw is CVE-2026-20184 in Cisco Webex Services with SSO integration via Control Hub - it allows an unauthenticated remote attacker to impersonate any user in the service due to incorrect certificate validation in the SSO flow. This is particularly dangerous for organizations using Webex with SAML and centralized identity management. Alongside it: CVE-2026-20180 and CVE-2026-20186 (both CVSS 9.9) affect Cisco ISE and ISE Passive Identity Connector, allowing authenticated attackers with even read-only admin credentials to execute arbitrary commands on the underlying OS and escalate to root. CVE-2026-20147 is a path traversal flaw in the same products. ISE versions before 3.2, plus 3.2, 3.3, 3.4, and 3.5 branches are all affected. No workarounds - only software updates fix these. In single-node ISE deployments, exploitation can also knock the node offline, blocking network access for unauthenticated endpoints.

Check
If you use Cisco Webex with SSO via Control Hub, treat CVE-2026-20184 as urgent - it's unauthenticated. If you run Cisco ISE for network access control, plan to patch this week.
Affected
Cisco Webex Services configured with SSO integration via Control Hub (CVE-2026-20184, unauthenticated impersonation). Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) versions prior to 3.2, plus 3.2, 3.3, 3.4, and 3.5 branches (CVE-2026-20180, CVE-2026-20186, CVE-2026-20147).
Fix
Apply Cisco's software updates from the April 15 advisories. For ISE, upgrade to the fixed release matching your branch - there are no workarounds. For Webex with SSO, the fix is included in Cisco's latest Control Hub release. If patching is delayed, restrict admin access to ISE management interfaces to trusted IPs only via network-level ACLs - this doesn't fix CVE-2026-20184 but reduces the risk from ISE credential theft to RCE chains. Review Cisco admin account hygiene: read-only credentials are enough to chain to root on unpatched ISE.