CVE-2026-21391Improper Claim Validation in PingAM OIDC Provider Exploitation status Not confirmed Fix YesAffected product P PingAM Published 09/14/2026 Severity Critical CVE-2026-20773Improper Authorization in PingFederate Administrative Expression Evaluation Endpoint Exploitation status Not known exploited Fix YesAffected product P PingFederate Published 09/14/2026 Severity High CVE-2025-32736PingFederate Administrative Console CSRF weaknesses Exploitation status Not known exploited Fix YesAffected product P PingFederate Published 08/10/2026 Severity Medium CVE-2026-20746PingDirectory copying of virtual attributes leads to memory exhaustion Exploitation status Not known exploited Fix YesAffected product P PingDirectory Published 06/12/2026 Severity Medium CVE-2025-20628Insufficient granularity of access control for Remote Connector Servers in client mode Exploitation status Not known exploited Fix YesAffected product P PingIDM Published 04/07/2026 Severity Medium CVE-2025-27935Authentication Bypass in OTP (One-time Passcode) IdP Adapter Integration Kit Exploitation status Not known exploited Fix Not confirmed Affected product O One-Time Passcode Integration Kit for PingFederate Published 12/04/2025 Severity High CVE-2025-26862PingFederate unexpected browser flow initiation in redirectless mode Exploitation status Not known exploited Fix YesAffected product P PingFederate Published 10/27/2025 Severity Informational CVE-2024-25573Stored Cross-Site Scripting in Administrative Console Context Exploitation status Not known exploited Fix YesAffected product P PingFederate Published 06/15/2025 Severity Medium CVE-2025-22854Possible thread exhaustion from processing http responses in PingFederate Google Adapter Exploitation status Not known exploited Fix YesAffected product P PingFederate Published 06/15/2025 Severity Medium CVE-2025-21085PingFederate OAuth Grant attribute duplication may use excessive memory Exploitation status Not known exploited Fix YesAffected product P PingFederate Published 06/15/2025 Severity Low CVE-2025-20059PingAM Java Policy Agent path traversal Exploitation status Not known exploited Fix Not confirmed Affected product P PingAM Java Policy Agent Published 02/20/2025 Severity Critical CVE-2024-23983Access rules for PingAccess may be circumvented with URL-encoded characters Exploitation status Not known exploited Fix YesAffected product P PingAccess Published 11/11/2024 Severity Medium CVE-2024-25566Open Redirect in PingAM Exploitation status Not known exploited Fix Not confirmed Affected product P PingAM Published 10/29/2024 Severity Medium CVE-2024-23600PingIDM Query Filter Vulnerability Exploitation status Not known exploited Fix Not confirmed Affected product P PingIDM Published 08/01/2024 Severity Low CVE-2024-21832PingFederate REST API Data Store Injection Exploitation status Not known exploited Fix YesAffected product P PingFederate Published 07/09/2024 Severity Low CVE-2024-22377PingFederate Runtime Node Path Traversal Exploitation status Not known exploited Fix YesAffected product P PingFederate Published 07/09/2024 Severity Medium CVE-2024-22477PingFederate OIDC Policy Management Editor Cross-Site Scripting Exploitation status Not known exploited Fix YesAffected product P PingFederate Published 07/09/2024 Severity Low CVE-2023-40356PingOne MFA Integration Kit MFA bypass Exploitation status Not known exploited Fix YesAffected product P PingOne MFA Integration Kit for PingFederate Published 07/09/2024 Severity High CVE-2023-40702PingOne MFA Integration Kit MFA bypass Exploitation status Not known exploited Fix YesAffected product P PingOne MFA Integration Kit for PingFederate Published 07/09/2024 Severity High CVE-2024-23316PingAccess HTTP Request Desynchronization Weakness Exploitation status Not known exploited Fix YesAffected product P PingAccess Published 05/31/2024 Severity High CVE-2023-40148PingFederate Server Side Request Forgery vulnerability Exploitation status Not known exploited Fix YesAffected product P PingFederate Published 04/10/2024 Severity Medium CVE-2023-40545PingFederate OAuth client_secret_jwt Authentication Bypass Exploitation status Not known exploited Fix YesAffected product P PingFederate Published 02/06/2024 Severity High CVE-2023-36496Delegated Admin Virtual Attribute Provider Privilege Escalation Exploitation status Not known exploited Fix YesAffected product P PingDirectory Published 02/01/2024 Severity High CVE-2023-34085User Attribute Disclosure via DynamoDB Data Stores Exploitation status Not known exploited Fix YesAffected product P PingFederate Published 10/25/2023 Severity Low CVE-2023-39219Admin Console Denial of Service via Java class enumeration Exploitation status Not known exploited Fix YesAffected product P PingFederate Published 10/25/2023 Severity High CVE-2023-37283Authentication Bypass via HTML Form & Identifier First Adapter Exploitation status Not confirmed Fix YesAffected product P PingFederate Published 10/25/2023 Severity High CVE-2023-39930PingFederate PingID Radius PCV Authentication Bypass Exploitation status Not known exploited Fix YesAffected product P PingID Radius PCV Published 10/24/2023 Severity High CVE-2023-39231PingFederate PingOne MFA IK Device Pairing Second Factor Authentication Bypass Exploitation status Not known exploited Fix YesAffected product P PingOne MFA Integration Kit Published 10/24/2023 Severity High CVE-2022-40723Configuration-based MFA Bypass in PingID RADIUS PCV. Exploitation status Not known exploited Fix YesAffected product P PingID Radius PCV Published 04/25/2023 Severity Medium CVE-2022-23721PingID integration for Windows login duplicate username collision. Exploitation status Not known exploited Fix YesAffected product Not confirmed Published 04/25/2023 Severity Low CVE-2022-40725PingID Desktop PIN attempt lockout bypass. Exploitation status Not known exploited Fix YesAffected product P PingID Desktop for Windows Published 04/25/2023 Severity High CVE-2022-40724Cross-Site Request Forgery on PingFederate Local Identity Profiles Endpoint. Exploitation status Not known exploited Fix YesAffected product P PingFederate Published 04/25/2023 Severity Medium CVE-2022-40722Misconfiguration of RSA padding for offline MFA in the PingID Adapter for PingFederate. Exploitation status Not known exploited Fix YesAffected product P PingID Adapter for PingFederate Published 04/25/2023 Severity High CVE-2018-25084Ping Identity Self-Service Account Manager SSAMController.java cross site scripting Exploitation status Not confirmed Fix YesAffected product S Self-Service Account Manager Published 04/10/2023 Severity Low CVE-2022-23726Exploitation status Not known exploited Fix YesAffected product P PingCentral Published 09/30/2022 Severity Medium CVE-2022-23725PingID Windows Login prior to 2.8 does not properly set permissions on the Windows Registry entries used to store sensitive API keys under some circumstances Exploitation status Not confirmed Fix YesAffected product P PingID Windows Login Published 06/30/2022 Severity High CVE-2022-23720PingID Windows Login prior to 2.8 does not alert or halt operation if it has been provisioned with the full permissions PingID properties file Exploitation status Not confirmed Fix YesAffected product P PingID Windows Login Published 06/30/2022 Severity High CVE-2022-23719PingID Windows Login prior to 2.8 does not authenticate communication with a local Java service used to capture security key requests Exploitation status Not confirmed Fix YesAffected product P PingID Windows Login Published 06/30/2022 Severity High CVE-2022-23718PingID Windows Login prior to 2.8 uses known vulnerable components that can lead to remote code execution Exploitation status Not confirmed Fix YesAffected product P PingID Windows Login Published 06/30/2022 Severity High CVE-2022-23717PingID Windows Login prior to 2.8 denial of service condition Exploitation status Not confirmed Fix YesAffected product P PingID Windows Login Published 06/30/2022 Severity Medium CVE-2021-41995PingID Mac Login prior to 1.1 vulnerable to pre-computed dictionary attacks Exploitation status Not confirmed Fix YesAffected product P PingID Mac Login Published 06/30/2022 Severity High CVE-2022-23724PingID Integration for Windows Login MFA Bypass Exploitation status Not confirmed Fix Not confirmed Affected product P PingID Integration for Windows Login Published 05/04/2022 Severity Medium CVE-2022-23723PingFederate PingOneMFA Integration Kit MFA Bypass Exploitation status Not confirmed Fix Not confirmed Affected product P PingFederate PingOne MFA Integration Kit Published 05/02/2022 Severity High CVE-2022-23722PingFederate Password Reset via Authentication API Mishandling Exploitation status Not confirmed Fix Not confirmed Affected product P PingFederate Published 05/02/2022 Severity Unknown CVE-2021-42001PingID Desktop encryption libraries misconfiguration can lead to sensitive data exposure Exploitation status Not confirmed Fix YesAffected product P PingID Desktop Published 04/30/2022 Severity High CVE-2021-41994PingID iOS mobile application prior to 1.19 vulnerable to pre-computed dictionary attacks Exploitation status Not confirmed Fix YesAffected product P PingID Mobile Application Published 04/30/2022 Severity Medium CVE-2021-41993PingID Android mobile application prior to 1.19 vulnerable to pre-computed dictionary attacks Exploitation status Not confirmed Fix YesAffected product P PingID Mobile Application Published 04/30/2022 Severity Medium CVE-2021-41992PingID Windows Login RSA cryptographic weakness with possible offline MFA bypass Exploitation status Not confirmed Fix YesAffected product P PingID Windows Login Published 04/30/2022 Severity High CVE-2021-42000Ping Identity PingFederate Password Reset and Password Change Mishandling with an authentication policy in parallel reset flows Exploitation status Not confirmed Fix YesAffected product P PingFederate Published 02/10/2022 Severity Medium CVE-2021-40329Exploitation status Not confirmed Fix Not confirmed Affected product P PingFederate Published 09/27/2021 Severity Unknown CVE-2021-31923Exploitation status Not confirmed Fix Not confirmed Affected product P PingAccess Published 09/24/2021 Severity Unknown CVE-2021-39270Exploitation status Not confirmed Fix Not confirmed Affected product R RSA SecurID Integration Kit Published 08/18/2021 Severity Unknown