Skip to content
English

Products › IT administration and security

IT administration and security

Identity and access

Directories, single sign-on, access management and privileged account management.

For example: Active Directory, AD FS, Cisco ISE, Workspace ONE Access.

Category RSS feed

Affected brands

In alphabetical order, with their number of vulnerabilities in this category.

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

See also

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.

  1. Rank 1Cisco Identity Services Engine (ISE)

    CVE-2026-76460

    Recently addedHunt for compromise (CISA)

    Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 16, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  2. Rank 2Oracle Identity and Access Management (OIM / OAM)

    CVE-2025-61757

    Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Nov 21, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  3. Rank 3Microsoft AD FS

    CVE-2026-56155

    Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 14, 2026
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  4. Rank 4Cisco Identity Services Engine (ISE)

    CVE-2025-20281

    Cisco Identity Services Engine Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 28, 2025
    CISA deadline
    21 days
    CVSS severity
    10.0 (critical)
  5. Rank 5Cisco Identity Services Engine (ISE)

    CVE-2025-20337

    Cisco Identity Services Engine Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 28, 2025
    CISA deadline
    21 days
    CVSS severity
    10.0 (critical)
  6. Rank 6Microsoft Active Directory

    CVE-2020-1472

    Ransomware

    Microsoft Netlogon Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    10.0 (critical)
  7. Rank 7Netwrix Auditor

    CVE-2022-31199

    Ransomware

    Netwrix Auditor Insecure Object Deserialization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 11, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  8. Rank 8Oracle Identity and Access Management (OIM / OAM)

    CVE-2021-35587

    Oracle Fusion Middleware Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 28, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  9. Rank 9ManageEngine (Zoho) PAM360 / Password Manager Pro

    CVE-2022-35405

    Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 22, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  10. Rank 10VMware (Broadcom) Workspace ONE Access / Identity Manager

    CVE-2022-22954

    Ransomware

    VMware Workspace ONE Access and Identity Manager Server-Side Template Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 14, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
Show 14 more vulnerabilities
  1. Rank 11Cisco Secure Access Control System (ACS)

    CVE-2018-0147

    CVE from 2018, added in 2022

    Cisco Secure Access Control System Java Deserialization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  2. Rank 12Atlassian Crowd

    CVE-2019-11580

    RansomwareCVE from 2019, added in 2021

    Atlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  3. Rank 13ForgeRock Access Management (AM)

    CVE-2021-35464

    Ransomware

    ForgeRock Access Management (AM) Core Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  4. Rank 14ManageEngine (Zoho) ADSelfService Plus

    CVE-2021-40539

    Ransomware

    Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  5. Rank 15VMware (Broadcom) Workspace ONE Access / Identity Manager

    CVE-2020-4006

    Multiple VMware Products Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.1 (critical)
  6. Rank 16Microsoft Active Directory

    CVE-2022-26923

    Microsoft Active Directory Domain Services Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 18, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  7. Rank 17Microsoft Active Directory

    CVE-2021-42287

    Ransomware

    Microsoft Active Directory Domain Services Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 11, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  8. Rank 18Microsoft Active Directory

    CVE-2014-6324

    CVE from 2014, added in 2022

    Microsoft Kerberos Key Distribution Center (KDC) Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  9. Rank 19VMware (Broadcom) Workspace ONE Access / Identity Manager

    CVE-2022-22960

    VMware Multiple Products Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 15, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  10. Rank 20Microsoft Active Directory

    CVE-2021-42278

    Ransomware

    Microsoft Active Directory Domain Services Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 11, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  11. Rank 21OpenText (Micro Focus) Access Manager (NetIQ)

    CVE-2021-22506

    Micro Focus Access Manager Information Leakage Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.5 (high)
  12. Rank 22ManageEngine (Zoho) ADSelfService Plus

    CVE-2022-28810

    Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 7, 2023
    CISA deadline
    21 days
    CVSS severity
    6.8 (medium)
  13. Rank 23Twilio Authy

    CVE-2024-39891

    Twilio Authy Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 23, 2024
    CISA deadline
    21 days
    CVSS severity
    5.3 (medium)
  14. Rank 24Oracle Identity and Access Management (OIM / OAM)

    CVE-2012-0518

    CVE from 2012, added in 2022

    Oracle Fusion Middleware Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    4.7 (medium)

Filed under another category

These 8 vulnerabilities also concern this type of product, but are counted in their main category. My radar finds them when you follow this category.

  1. BeyondTrust Remote Support / Privileged Remote Access (RS / PRA)

    CVE-2026-1731

    Ransomware

    BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 13, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  2. BeyondTrust Remote Support / Privileged Remote Access (RS / PRA)

    CVE-2024-12356

    BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 19, 2024
    CISA deadline
    8 days
    CVSS severity
    9.8 (critical)
  3. Microsoft Windows

    CVE-2014-1812

    RansomwareCVE from 2014, added in 2021

    Microsoft Windows Group Policy Preferences Password Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  4. Microsoft Windows

    CVE-2021-36942

    Ransomware

    Microsoft Windows Local Security Authority (LSA) Spoofing Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.5 (high)
  5. BeyondTrust Remote Support / Privileged Remote Access (RS / PRA)

    CVE-2024-12686

    BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 13, 2025
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
Show 3 more vulnerabilities
  1. Microsoft Windows

    CVE-2024-43451

    Microsoft Windows NTLMv2 Hash Disclosure Spoofing Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 12, 2024
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  2. Microsoft Windows

    CVE-2022-26925

    Microsoft Windows LSA Spoofing Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 1, 2022
    CISA deadline
    21 days
    CVSS severity
    5.9 (medium)
  3. Microsoft Windows

    CVE-2025-24054

    Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 17, 2025
    CISA deadline
    21 days
    CVSS severity
    5.4 (medium)

Follow and verify

Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.