Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ping Identity Corporation

First CVE: Dec 12, 2014Active for: 12 yearsTotal CVEs: 48
20.4
VTI Score
Low

Ping Identity Corporation develops a focused suite of identity and access management products, with PingFederate and PingID forming the core of its authentication and federation infrastructure deployed across enterprise environments. The vendor's vulnerability profile skews toward serious outcomes, with a meaningful share reaching critical severity, reflecting the privileged role these products occupy in authentication pathways and identity trust decisions. The durable signal clusters around authentication-related weaknesses—including authentication bypass through alternate channels, improper or missing authentication controls, and input-validation issues in web-facing components—which are characteristic of identity platforms where flaws can cascade across downstream applications and services. Defenders should prioritize this vendor's security advisories for authentication and federation products and treat identity-layer patches as broadly applicable across their service infrastructure. Current exploitation activity and severity figures are shown alongside this summary.

FAUCET AI Generated
48
Total CVEs
More Total CVEs than 98% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ping Identity Corporation over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 12, 2014
11 years ago
Most Recent CVE
Jun 12, 2026
42 days ago

Self-Reporting Analysis

Of all the CVEs published by Ping Identity Corporation as a CNA, 85.7% affect products that Ping Identity Corporation develops as a vendor.

85.7%
14.3%
Self-reported: 42 (85.7%)
Third-party: 7 (14.3%)

Of all the CVEs published that affect products developed by Ping Identity Corporation, 87.5% are self-published by Ping Identity Corporation as a CNA.

87.5%
12.5%
Self-published: 42 (87.5%)
Other CNAs: 6 (12.5%)

Products(20 total)

Top CVEs

Signals from CVEs in this vendor scope (48 CVEs).

48 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-42001CRITICAL
PingID Desktop prior to 1.7.3 has a misconfiguration in the encryption libraries which can lead to sensitive data exposure. An attacker capable of exploiting this vulnerability may
Apr 30, 20229.931NONO
CVE-2018-1000134CRITICAL
UnboundID LDAP SDK version from commit 801111d8b5c732266a5dbd4b3bb0b6c7b94d7afb up to commit 8471904a02438c03965d21367890276bc25fa5a6, where the issue was reported and fixed contai
Mar 16, 20189.831NONO
CVE-2021-40329CRITICAL
The Authentication API in Ping Identity PingFederate before 10.3 mishandles certain aspects of external password management.
Sep 27, 20219.830NONO
CVE-2023-40545CRITICAL
Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 versions via specially crafted requests.
Feb 6, 20249.827NONO
CVE-2022-40724HIGH
The PingFederate Local Identity Profiles '/pf/idprofile.ping' endpoint is vulnerable to Cross-Site Request Forgery (CSRF) through crafted GET requests.
Apr 25, 20238.827NONO
CVE-2023-39930CRITICAL
A first-factor authentication bypass vulnerability exists in the PingFederate with PingID Radius PCV when a MSCHAP authentication request is sent via a maliciously crafted RADIUS c
Oct 25, 20239.826NONO
CVE-2026-20746MEDIUM
Virtual attribute handling in Ping Identity PingDirectory in affected versions allows only authorized users to exhaust java memory heap when recent login history is enabled and cop
Jun 12, 20266.325NONO
CVE-2024-23316HIGH
HTTP request desynchronization in Ping Identity PingAccess, all versions prior to 8.0.1 affected allows an attacker to send specially crafted http header requests to create a reque
May 31, 20248.825NONO
CVE-2023-37283CRITICAL
Under a very specific and highly unrecommended configuration, authentication bypass is possible in the PingFederate Identifier First Adapter
Oct 25, 20239.825NONO
CVE-2022-23720HIGH
PingID Windows Login prior to 2.8 does not alert or halt operation if it has been provisioned with the full permissions PingID properties file. An IT administrator could mistakenly
Jun 30, 20228.225NONO
View all 48 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products48 CVEs
52%
25%
15%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCriticalNone
Attack Vector
Local8 (16.7%)
Network36 (75.0%)
Unknown1 (2.1%)
Physical2 (4.2%)
Adjacent Network1 (2.1%)
Attack Complexity
Low38 (79.2%)
High9 (18.8%)
Unknown1 (2.1%)
User Interaction
None36 (75.0%)
Unknown1 (2.1%)
Required4 (8.3%)
Privileges Required
Low21 (43.8%)
High7 (14.6%)
None19 (39.6%)
Unknown1 (2.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (48 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ping Identity Corporation.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ping Identity Corporation — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ping Identity Corporation's Products

View all 3 CNAs →

Top CWEs