Ping Identity Corporation
Self-Reporting Analysis
Of all the CVEs published by Ping Identity Corporation as a CNA, 85.7% affect products that Ping Identity Corporation develops as a vendor.
Of all the CVEs published that affect products developed by Ping Identity Corporation, 87.5% are self-published by Ping Identity Corporation as a CNA.
Trends Over Time
The number and severity of CVEs published by Ping Identity Corporation over time
Top CVEs
All CVEs published by Ping Identity Corporation as a CNA, regardless of affected vendor or product.
49 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-42001CRITICAL PingID Desktop prior to 1.7.3 has a misconfiguration in the encryption libraries which can lead to sensitive data exposure. An attacker capable of exploiting this vulnerability may | Apr 30, 2022 | 9.9 | 31 | NO | NO |
CVE-2021-40329CRITICAL The Authentication API in Ping Identity PingFederate before 10.3 mishandles certain aspects of external password management. | Sep 27, 2021 | 9.8 | 30 | NO | NO |
CVE-2023-40545CRITICAL Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 versions via specially crafted requests.
| Feb 6, 2024 | 9.8 | 27 | NO | NO |
CVE-2022-40724HIGH The PingFederate Local Identity Profiles '/pf/idprofile.ping' endpoint is vulnerable to Cross-Site Request Forgery (CSRF) through crafted GET requests. | Apr 25, 2023 | 8.8 | 27 | NO | NO |
CVE-2025-27935HIGH The OTP Integration Kit for PingFederate fails to enforce HTTP method validation and state validation properly. The server advances the authentication state without verifying the O | Dec 4, 2025 | 8.6 | 26 | NO | NO |
CVE-2023-39930CRITICAL A first-factor authentication bypass vulnerability exists in the PingFederate with PingID Radius PCV when a MSCHAP authentication request is sent via a maliciously crafted RADIUS c | Oct 25, 2023 | 9.8 | 26 | NO | NO |
CVE-2026-20746MEDIUM Virtual attribute handling in Ping Identity PingDirectory in affected versions allows only authorized users to exhaust java memory heap when recent login history is enabled and cop | Jun 12, 2026 | 6.3 | 25 | NO | NO |
CVE-2025-20059CRITICAL Relative Path Traversal vulnerability in Ping Identity PingAM Java Policy Agent allows Parameter Injection.This issue affects PingAM Java Policy Agent: through 5.10.3, through 2023 | Feb 20, 2025 | 9.1 | 25 | NO | NO |
CVE-2024-23316HIGH HTTP request desynchronization in Ping Identity PingAccess, all versions prior to 8.0.1 affected allows an attacker to send specially crafted http header requests to create a reque | May 31, 2024 | 8.8 | 25 | NO | NO |
CVE-2023-37283CRITICAL Under a very specific and highly unrecommended configuration, authentication bypass is possible in the PingFederate Identifier First Adapter
| Oct 25, 2023 | 9.8 | 25 | NO | NO |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this cna scope (49 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID published by Ping Identity Corporation as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Ping Identity Corporation as a CNA — matched by CVE ID, not by organization name.