Ping Identity Corporation develops a focused suite of identity and access management products, with PingFederate and PingID forming the core of its authentication and federation infrastructure deployed across enterprise environments. The vendor's vulnerability profile skews toward serious outcomes, with a meaningful share reaching critical severity, reflecting the privileged role these products occupy in authentication pathways and identity trust decisions. The durable signal clusters around authentication-related weaknesses—including authentication bypass through alternate channels, improper or missing authentication controls, and input-validation issues in web-facing components—which are characteristic of identity platforms where flaws can cascade across downstream applications and services. Defenders should prioritize this vendor's security advisories for authentication and federation products and treat identity-layer patches as broadly applicable across their service infrastructure. Current exploitation activity and severity figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ping Identity Corporation over time
Of all the CVEs published by Ping Identity Corporation as a CNA, 85.7% affect products that Ping Identity Corporation develops as a vendor.
Of all the CVEs published that affect products developed by Ping Identity Corporation, 87.5% are self-published by Ping Identity Corporation as a CNA.
Signals from CVEs in this vendor scope (48 CVEs).
48 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-42001CRITICAL PingID Desktop prior to 1.7.3 has a misconfiguration in the encryption libraries which can lead to sensitive data exposure. An attacker capable of exploiting this vulnerability may | Apr 30, 2022 | 9.9 | 31 | NO | NO |
CVE-2018-1000134CRITICAL UnboundID LDAP SDK version from commit 801111d8b5c732266a5dbd4b3bb0b6c7b94d7afb up to commit 8471904a02438c03965d21367890276bc25fa5a6, where the issue was reported and fixed contai | Mar 16, 2018 | 9.8 | 31 | NO | NO |
CVE-2021-40329CRITICAL The Authentication API in Ping Identity PingFederate before 10.3 mishandles certain aspects of external password management. | Sep 27, 2021 | 9.8 | 30 | NO | NO |
CVE-2023-40545CRITICAL Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 versions via specially crafted requests.
| Feb 6, 2024 | 9.8 | 27 | NO | NO |
CVE-2022-40724HIGH The PingFederate Local Identity Profiles '/pf/idprofile.ping' endpoint is vulnerable to Cross-Site Request Forgery (CSRF) through crafted GET requests. | Apr 25, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-39930CRITICAL A first-factor authentication bypass vulnerability exists in the PingFederate with PingID Radius PCV when a MSCHAP authentication request is sent via a maliciously crafted RADIUS c | Oct 25, 2023 | 9.8 | 26 | NO | NO |
CVE-2026-20746MEDIUM Virtual attribute handling in Ping Identity PingDirectory in affected versions allows only authorized users to exhaust java memory heap when recent login history is enabled and cop | Jun 12, 2026 | 6.3 | 25 | NO | NO |
CVE-2024-23316HIGH HTTP request desynchronization in Ping Identity PingAccess, all versions prior to 8.0.1 affected allows an attacker to send specially crafted http header requests to create a reque | May 31, 2024 | 8.8 | 25 | NO | NO |
CVE-2023-37283CRITICAL Under a very specific and highly unrecommended configuration, authentication bypass is possible in the PingFederate Identifier First Adapter
| Oct 25, 2023 | 9.8 | 25 | NO | NO |
CVE-2022-23720HIGH PingID Windows Login prior to 2.8 does not alert or halt operation if it has been provisioned with the full permissions PingID properties file. An IT administrator could mistakenly | Jun 30, 2022 | 8.2 | 25 | NO | NO |
Signals from CVEs in this vendor scope (48 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ping Identity Corporation.
Media articles that mention a CVE ID that affects a product developed by Ping Identity Corporation — matched by CVE ID, not by vendor name.