<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://exploit-radar.com/en/flux/categories/identite.xml</id>
  <title>Exploit Radar: Identity and access</title>
  <subtitle>The latest additions to CISA’s catalog of exploited vulnerabilities in the “Identity and access” category (indicative classification).</subtitle>
  <link rel="self" type="application/atom+xml" href="https://exploit-radar.com/en/flux/categories/identite.xml"/>
  <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/produits/identite/"/>
  <updated>2026-09-16T00:00:00Z</updated>
  <author><name>Exploit Radar</name></author>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-76460/</id>
    <title>CVE-2026-76460 — Cisco Identity Services Engine (ISE)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-76460/"/>
    <updated>2026-09-16T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Cisco; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on September 16, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-56155/</id>
    <title>CVE-2026-56155 — Microsoft AD FS</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-56155/"/>
    <updated>2026-07-14T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Microsoft; if none are available, stop using the product. Start with internet-facing devices. CISA deadline: 14 days. Added to CISA’s catalog of exploited vulnerabilities on July 14, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-61757/</id>
    <title>CVE-2025-61757 — Oracle Identity and Access Management (OIM / OAM)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-61757/"/>
    <updated>2025-11-21T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Oracle; if none are available, stop using the product. For cloud services, follow the guidance from Oracle. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on November 21, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-20281/</id>
    <title>CVE-2025-20281 — Cisco Identity Services Engine (ISE)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-20281/"/>
    <updated>2025-07-28T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Cisco; if none are available, stop using the product. For cloud services, follow the guidance from Cisco. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on July 28, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-20337/</id>
    <title>CVE-2025-20337 — Cisco Identity Services Engine (ISE)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-20337/"/>
    <updated>2025-07-28T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Cisco; if none are available, stop using the product. For cloud services, follow the guidance from Cisco. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on July 28, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2024-39891/</id>
    <title>CVE-2024-39891 — Twilio Authy</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2024-39891/"/>
    <updated>2024-07-23T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Twilio; if none are available, stop using the product. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on July 23, 2024.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2022-31199/</id>
    <title>CVE-2022-31199 — Netwrix Auditor</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2022-31199/"/>
    <updated>2023-07-11T00:00:00Z</updated>
    <summary type="text">Apply the update from Netwrix; if none are available, stop using the product. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on July 11, 2023.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2022-28810/</id>
    <title>CVE-2022-28810 — ManageEngine (Zoho) ADSelfService Plus</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2022-28810/"/>
    <updated>2023-03-07T00:00:00Z</updated>
    <summary type="text">Apply the security update from ManageEngine (Zoho). CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on March 7, 2023.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-35587/</id>
    <title>CVE-2021-35587 — Oracle Identity and Access Management (OIM / OAM)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-35587/"/>
    <updated>2022-11-28T00:00:00Z</updated>
    <summary type="text">Apply the security update from Oracle. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on November 28, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2022-35405/</id>
    <title>CVE-2022-35405 — ManageEngine (Zoho) PAM360 / Password Manager Pro</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2022-35405/"/>
    <updated>2022-09-22T00:00:00Z</updated>
    <summary type="text">Apply the security update from ManageEngine (Zoho). CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on September 22, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2022-26923/</id>
    <title>CVE-2022-26923 — Microsoft Active Directory</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2022-26923/"/>
    <updated>2022-08-18T00:00:00Z</updated>
    <summary type="text">Apply the security update from Microsoft. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on August 18, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2022-22960/</id>
    <title>CVE-2022-22960 — VMware (Broadcom) Workspace ONE Access / Identity Manager</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2022-22960/"/>
    <updated>2022-04-15T00:00:00Z</updated>
    <summary type="text">Apply the security update from VMware (Broadcom). CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on April 15, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2022-22954/</id>
    <title>CVE-2022-22954 — VMware (Broadcom) Workspace ONE Access / Identity Manager</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2022-22954/"/>
    <updated>2022-04-14T00:00:00Z</updated>
    <summary type="text">Apply the security update from VMware (Broadcom). CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on April 14, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-42287/</id>
    <title>CVE-2021-42287 — Microsoft Active Directory</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-42287/"/>
    <updated>2022-04-11T00:00:00Z</updated>
    <summary type="text">Apply the security update from Microsoft. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on April 11, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-42278/</id>
    <title>CVE-2021-42278 — Microsoft Active Directory</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-42278/"/>
    <updated>2022-04-11T00:00:00Z</updated>
    <summary type="text">Apply the security update from Microsoft. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on April 11, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2012-0518/</id>
    <title>CVE-2012-0518 — Oracle Identity and Access Management (OIM / OAM)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2012-0518/"/>
    <updated>2022-03-28T00:00:00Z</updated>
    <summary type="text">Apply the security update from Oracle. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on March 28, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2018-0147/</id>
    <title>CVE-2018-0147 — Cisco Secure Access Control System (ACS)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2018-0147/"/>
    <updated>2022-03-25T00:00:00Z</updated>
    <summary type="text">Apply the security update from Cisco. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on March 25, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2014-6324/</id>
    <title>CVE-2014-6324 — Microsoft Active Directory</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2014-6324/"/>
    <updated>2022-03-25T00:00:00Z</updated>
    <summary type="text">Apply the security update from Microsoft. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on March 25, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2020-1472/</id>
    <title>CVE-2020-1472 — Microsoft Active Directory</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2020-1472/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from Microsoft. CISA deadline: 181 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2019-11580/</id>
    <title>CVE-2019-11580 — Atlassian Crowd</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2019-11580/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from Atlassian. CISA deadline: 181 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-35464/</id>
    <title>CVE-2021-35464 — ForgeRock Access Management (AM)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-35464/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from ForgeRock. CISA deadline: 14 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-40539/</id>
    <title>CVE-2021-40539 — ManageEngine (Zoho) ADSelfService Plus</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-40539/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from ManageEngine (Zoho). CISA deadline: 14 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2020-4006/</id>
    <title>CVE-2020-4006 — VMware (Broadcom) Workspace ONE Access / Identity Manager</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2020-4006/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from VMware (Broadcom). CISA deadline: 181 days. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-22506/</id>
    <title>CVE-2021-22506 — OpenText (Micro Focus) Access Manager (NetIQ)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-22506/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from OpenText (Micro Focus). CISA deadline: 14 days. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
</feed>
