CyberArk: CA26-39, CA26-40, CA26-41, CA26-42, CA26-43 and CA26-44
Dear Customers, On Wednesday, Sep 2, Idira (formerly CyberArk) has released High and Critical Severity Security Bulletins.
Please review whether any affected component versions are present within your environment and prioritize remediation efforts based on the severity and business impact outlined in the associated security bulletins.
CA26-39 involves a High severity issue that affects EPM SaaS Windows Agents, all versions prior to 26.8.
CA26-40 involves a High severity issue that affects EPM SaaS Windows Agents, all versions prior to 26.8.
CA26-41 involves a High severity issue that affects EPM SaaS Windows Agents, all versions prior to 26.8.
CA26-42 involves a High severity issue that affects HTML5 Gateway Container and RPM, Self-Hosted, version 15.2 14.6 14.2 14.0.
CA26-43 involves a High severity issue that affects Password Vault Web Access, Self-Hosted, all 15.2 versions prior to version 15.2.2 All 14.6 versions prior to version 14.6.5.
CA26-44 involves a Critical severity issue that affects Password Vault Web Access, Self-Hosted, all 15.2 versions prior to version 15.2.2 All 14.6 versions prior to version 14.6.5 All 14.2 versions prior to version 14.2.7 All 14.0 versions prior to version 14.0.9.
For complete details on the vulnerabilities, recommendations, and update instructions, please review the Security Bulletins, that can be found in the Technical Community:
https://community.cyberark.com/s/article/Idira-Security-Bulletin-CA26-39
https://community.cyberark.com/s/article/Idira-Security-Bulletin-CA26-40
https://community.cyberark.com/s/article/Idira-Security-Bulletin-CA26-41
https://community.cyberark.com/s/article/Idira-Security-Bulletin-CA26-42
https://community.cyberark.com/s/article/Idira-Security-Bulletin-CA26-43
https://community.cyberark.com/s/article/Idira-Security-Bulletin-CA26-44
Learn more by visiting Product Security | CyberArk
CyberArk: CA26-37 / CA26-38
Dear Customers, On Wednesday, Aug 12, Idira (formerly CyberArk) has released High Severity Security Bulletins CA26-37 affecting Privilege Cloud Central Policy Manager (CPM), CA26-38 affecting Secrets Manager, Self Hosted.
Please review whether any affected component versions are present within your environment and prioritize remediation efforts based on the severity and business impact outlined in the associated security bulletins.
CA26-37 involves a High severity issue that affects Privilege Cloud Central Policy Manager (CPM), all versions prior to 15.0.
CA26-38 involves a High severity issue that affects Secrets Manager, Self Hosted, version 13.9.0.
For complete details on the vulnerabilities, recommendations, and update instructions, please review the Security Bulletins, that can be found in the Technical Community:
https://community.cyberark.com/s/article/Idira-Security-Bulletin-CA26-37
https://community.cyberark.com/s/article/Idira-Security-Bulletin-CA26-38
Learn more by visiting Product Security | CyberArk
CyberArk: CA26-35 / CA26-36
Dear Customers, On Wednesday, July 22, Idira (formerly CyberArk) has released Critical and High Severity Security Bulletins CA26-35, CA26-36 affecting z/OS Credential Provider, Terminal plugin controller (TPC),Microsoft Windows Local with WMI plugin, Database Credentials Management Framework versions.
Please review whether any affected components are present within your environment and prioritize remediation efforts based on the severity and business impact outlined in the associated security bulletins.
CA26-35 involves a Critical severity issue that affects z/OS Credential Provider, all versions prior to 14.2.7
CA26-36 involves a High severity issue that affects Terminal plugin controller (TPC), version 15.0.0 or earlier; Microsoft Windows Local with WMI plugin, version 21.0.1 or earlier; Database Credentials Management Framework, version 20.1.8 or earlier.
For complete details on the vulnerabilities, recommendations, and update instructions, please review the Security Bulletins, that can be found in the Technical Community:
https://www.cyberark.com/CA26-35
https://www.cyberark.com/CA26-36
Learn more by visiting Product Security | CyberArk
Wednesday, July 8th, CyberArk released Security Bulletins CA26-24, CA26-25, CA26-27, CA26-28 and CA26-29
CA26-24 involves a High severity issue that affects EPM SaaS Windows Agents, all versions prior to 26.6.
CA26-25 involves a High severity issue that affects EPM SaaS Windows Agents, all versions prior to 26.6.
CA26-27 involves a High severity issue that affects Privileged Threat Analytics, Idira PAM Self-Hosted, all versions prior to version 15.2 (exclusive).
CA26-28 involves a High severity issue that affects Vault/Infra, Self-Hosted, all versions prior to version 15.0.3 (inclusive).
CA26-29 involves a High severity issue that affects Remote Control Client, all versions prior to version 15.0.3 (inclusive).
For complete details on the vulnerabilities, recommendations, and update instructions, please review the Security Bulletins, that can be found in the Technical Community:
https://www.cyberark.com/CA26-24
https://www.cyberark.com/CA26-25
https://www.cyberark.com/CA26-27
https://www.cyberark.com/CA26-28
https://www.cyberark.com/CA26-29
Learn more by visiting Product Security | CyberArk
BeyondTrust Remote Support and Privileged Remote Access Security Advisory: BT26-03
Action Required
BeyondTrust has published Security Advisory BT26-03 (https://www.beyondtrust.com/trust-center/security-advisories) relating to multiple vulnerabilities affecting BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA).
Customers using self-hosted BeyondTrust Remote Support or Privileged Remote Access should review their current versions and ensure that the relevant security updates have been applied.
Impact
The advisory includes Critical and High severity vulnerabilities. The most severe vulnerabilities may allow an unauthenticated attacker to bypass access controls and gain unauthorised access to the appliance under specific configurations. Additional vulnerabilities may result in service disruption, unintended data access, or elevated access by an authenticated user with specific permissions.
The affected versions are:
- Remote Support RS 25.3.2 or lower
- Privileged Remote Access PRA 25.3.2 or lower
Current Status
BeyondTrust has confirmed that patches have already been applied to all RS/PRA cloud customers.
Self-hosted customers should apply the relevant April 2026 Security Rollup for their deployed version where automatic updates are not enabled, or upgrade to:
- Remote Support RS 25.3.3 or above
- Privileged Remote Access PRA 25.3.3 or above
Recommended Action
Customers should review the BeyondTrust BT26-03 Security Advisory and confirm whether their environment is affected.
Where required, customers should apply the relevant security rollup or upgrade to the fixed versions as soon as possible, particularly where Remote Support or Privileged Remote Access is externally accessible.
Advisory ID: BT26-02
CVE-2026-1731
BeyondTrust Remote Support and older versions of Privileged Remote Access contain a critical pre-authentication remote code execution vulnerability that may be triggered through specially crafted client requests. Successful exploitation could allow an unauthenticated remote attacker to execute operating system commands in the context of the site user and may lead to system compromise, including unauthorized access, data exfiltration, and service disruption.
- Synopsis: Remote code execution in Remote Support (RS) and Privileged Remote Access (PRA)
- Affected Product: Remote Support (RS) and Privileged Remote Access (PRA)
Observed exploitation activity has been limited to internet-facing, self-hosted environments where the patch had not been applied before February 9, 2026.
Important: BeyondTrust is strongly encouraging all self-hosted customers who had internet-exposed instances that remained unpatched as of February 9 to take immediate action to apply the recommended updates and open a “Severity 1” ticket to BeyondTrust support, citing “BT26-02” in the description.
Affected Versions:
Remote Support - 25.3.1 and prior
Privileged Remote Access - 24.3.4 and prior
CyberArk is now Idira® – Next-Generation Identity Security Platform
On June 8th, CyberArk announced its rebrand to Idira®, a next-generation identity security platform built on CyberArk's foundations and powered by Palo Alto Networks.
The transition is being rolled out in phases:
- Phase 1 (Visual updates): New Idira branding will begin appearing across the product UI, documentation, and automated system emails.
- Subsequent phases: Technical touchpoints such as product URLs and APIs will remain unchanged for now. Further updates will be communicated in advance.
For full details on what's changing, visit the Idira FAQ page.
CyberArk: CA26-23 - Incomplete IIS documentation for the z/OS Central Credential Provider (CCP) can cause weak authentication.
Impact: Incomplete configuration instructions in the documentation for the IIS that hosts the Central Credential Provider (CCP) for the z/OS Credential Provider can lead to weak authentication.
CA26-23 involves a Critical severity issue that affects:
- z/OS Credential Provider, all versions.
For complete details on the vulnerabilities, recommendations, and update instructions, please review the Security Bulletin, that can be found in the Technical Community:
https://www.cyberark.com/ca26-23
Learn more by visiting Product Security | CyberArk
CyberArk: CA26-22 - Possible Denial of Service (DoS) attack on HTML5 Gateway server.
Wednesday, May 20th, CyberArk released Security Bulletin: CA26-22.
Impact: Possible Denial of Service (DoS) attack on HTML5 Gateway server.
CA26-22 involves High severity issues that affects:
• HTML5 Gateway Container and RPM, Self-Hosted, All versions prior to version 15.0 (inclusive).
For complete details on the vulnerabilities, recommendations, and update instructions, please review the Security Bulletins, that can be found in the Technical Community (links below).
https://community.cyberark.com/s/article/CyberArk-Security-Bulletin-CA26-22
Learn more by visiting https://www.cyberark.com/product-security
CyberArk: CA26-17, CA26-18, CA26-19, CA26-20 and CA26-21
CyberArk has released five new security bulletins this week, collectively addressing high and critical severity vulnerabilities across a range of products, including Privileged Access Management, Endpoint Privilege Manager, Secrets Management, Privilege Cloud components and Identity browser extensions.
The bulletins impact both self‑hosted and SaaS deployments, with a particular focus on older product versions.
Affected components:
Self‑hosted PAM components, including PSM, PSMP and Vault infrastructure
Privilege Cloud Connector deployments
Endpoint Privilege Manager agents across Windows, macOS and Linux
Secrets Manager and Credential Provider components
CyberArk Identity Browser Extension
CA26-17: https://www.cyberark.com/CA26-17
CA26-18: https://www.cyberark.com/CA26-18
CA26-19: https://www.cyberark.com/CA26-19
CA26-20: https://www.cyberark.com/CA26-20
CA26-21: https://www.cyberark.com/CA26-21
CyberArk: CA26-15 / CA26-16 - Database Credentials Management Framework
Wednesday, May 5th, CyberArk released Security Bulletin CA26-15 and CA26-16.
CA26-15 involves a High severity issue that affects “Database Credentials Management Framework” marketplace Integration, all versions prior to version 20.1.5.
CA26-16 involves a High severity issue that affects “Database Credentials Management Framework” marketplace Integration, all versions prior to version 20.1.5.
The following CyberArk Security Bulletins provide information on the vulnerability, recommendations, and fix instructions:
CA26-15: https://www.cyberark.com/CA26-15
CA26-16: https://www.cyberark.com/CA26-16
Learn more by visiting https://www.cyberark.com/product-security.
SailPoint - New Capability: Workflow Limit Update by License Tiers
What is happening?
Workflows is increasing its Acceptable Use Limits for Business, Business Plus, and Atlas Enterprise suites:
Note: The limit on steps per workflow is unchanged.
Standards and Foundations - No chance in limits
Business - increased to 50 enabled workflows from 25
Business Plus - increased to 200 enabled workflows from 100
Atlas Enterprise - increased to 300 enabled workflows from 200
When is this happening?
- April 21st, 2026
Who is being impacted?
Business, Business Plus, and Atlas Enterprise customers.
CyberArk: CA26-14 - Prototype pollution in the Axios library
CyberArk have released Security Bulletin CA26-14 which describes Prototype pollution in the Axios library which is used by the PVWA servers in a self-hosted deployment.
Axios is a promise based HTTP client for the browser and Node.js that can be crashed causing complete denial of service. There is no temporary mitigation available for this, however, to CyberArk’s knowledge, this hasn’t been exploited in the wild.
CyberArk: Connect With Trusted RDP Files
SIA can now digitally sign RDP files with your organization's own certificate, eliminating the "Unknown Publisher" security warnings that previously created friction and eroded user trust during vaulted, ZSP, and JIT RDP sessions. This means end users get a seamless, warning-free connection experience with confidence that RDP launches genuinely originate from a trusted source.
Beyond the vault: Why Universal Privilege is the future of Privileged Access
SailPoint: Privilege Discovery and Classification / Privilege Insights
New Features:
Privilege Discovery and Classification:
SailPoint has introduced Privilege Discovery and Classification as a foundational component of SailPoint Identity Security Cloud. This capability is designed to help organizations automatically identify privileged entitlements across the enterprise, reducing the need for manual review and giving security teams broader visibility into where privileged access exists.
Classify Privilege by Risk:
With this enhancement, privileged entitlements can be classified by risk level, such as high, medium, or low. This helps organizations prioritize the access that matters most and focus effort on the entitlements that present the greatest potential exposure to the business.
Highlight Key Risk Areas:
These new capabilities help security teams visually pinpoint the areas of privileged access that create the highest risk. This gives teams a more practical way to understand where access-related exposure exists and where stronger controls may be needed.
Privilege Insights / Visualize Pathways to Privilege:
Through SailPoint Observability and Insights, security teams can now better understand how privilege is assigned, inherited, and exposed across identities. This includes visibility into direct privilege as well as hidden or overlapping pathways to privilege, helping organizations reduce unnecessary access and support a stronger least privilege model.
Support for Least Privilege at Scale:
SailPoint positions these capabilities as a way to make least privilege more achievable in large, fast-changing environments. Instead of relying on slow, manual analysis across massive entitlement sets, organizations can discover and evaluate privileged access much more efficiently. SailPoint states that work that previously could take years of manual analysis can now be done in days or hours.
Platform Availability:
These capabilities are available as part of SailPoint Identity Security Cloud and form part of SailPoint’s broader privilege security direction.
Further details available here:
Beyond the vault: Why Universal Privilege is the future of Privileged Access
Read more
CyberArk-Security-Bulletin-CA26-07
CyberArk customers should review the most recent security patch (released on 4th Feb) for applicability in their environments.
CA26-07 involves a High severity vulnerability that affects Credential Providers (CP), version 14.2 and all its patches prior 14.2.5.
https://community.cyberark.com/s/article/CyberArk-Security-Bulletin-CA26-07
Note: CCP and ASCP are not impacted by this vulnerability.
Remote Support / Privileged Remote Access - BT26-02 critical vulnerability patch for RS and PRA
BeyondTrust have released a Critical Vulnerability Patch. All Privileged Remote Access and Remote Support customers, particularly those with on-prem installations, should review details and apply mitigations where applicable.
Affected Version:
> Privileged Remote Access (PRA) version 24.3.4 and lower
> Remote Support 25.3.1 and lower
Patch details:
For SaaS Implementation:
> Patch BT26-02-PRA or BT26-02-RS has been applied to all SaaS instances as of February 2, 2026, that remediates this vulnerability.
For On-Premise Implementation:
> The vulnerability can be mitigated by upgrading to 25.1.1
CA26-02 & CA26-03: High Severity Vulnerabilities in Central Password Management
CyberArk has disclosed high severity vulnerabilities affecting Central Password Management in both self-hosted deployments (versions prior to 14.6.3) and Privilege Cloud environments (versions prior to 14.8). Customers should review the security bulletins (CA26-02, CA26-03) to understand their exposure and apply the recommended fixes as soon as possible.
SIA: Support for named instance connections in vaulted SQL Server targets
Secure Infrastructure Access (SIA) now supports connecting to specific SQL Server named instances by specifying the port and instance name when using vaulted credentials. Since enterprises commonly run multiple SQL instances on a single host, this closes a gap that previously made SIA impractical for complex database environments.
SIA: On-premises Windows connections to IP-based targets using ZSP
Secure Infrastructure Access (SIA) now allows users to establish RDP connections to on-prem Windows targets by IP address while maintaining Zero Standing Privileges. This is particularly useful for environments where DNS infrastructure or FQDNs aren't available, removing a common deployment blocker for extending ZSP coverage across legacy or segmented networks.
Enhance Security and Simplify Enrollment with Okta's Same Device Enrollment
Okta’s Same Device Enrolment streamlines and secures Okta Verify enrolment by allowing users to enrol on their current device using an OIDC flow, eliminating the need for QR codes, SMS, or email, which are vulnerable to interception. This approach enhances security, aligns with authentication policies, and provides a phishing-resistant, more intuitive enrolment experience. Organisations can choose to enforce Same Device Enrollment or offer it as an option alongside mobile-based methods.
The end of legacy IAM: why CrowdStrike and SGNL together changes everything
Why This Matters
- SGNL's continuous, context-aware authorization replaces outdated PAM and IGA solutions.
- Addresses real-time access management challenges, improving security posture.
- Offers a solution that balances security and usability for enterprises.
What Has Changed
- CrowdStrike acquires SGNL to deliver identity infrastructure that moves at the speed of threats.
- The combined platform enables real-time authorization decisions using comprehensive context.
- It allows enterprises to eliminate standing privileges and automate access decisions.
Timelines
- Immediate
Saviynt: 2026 Identity Security Trends & Predictions
Why This Matters
• AI adoption has outpaced security frameworks, creating governance gaps.
• Non-human identities (AI agents) now hold elevated privileges without proper oversight.
• Identity security has shifted from a support function to the foundation for AI resilience.
What Has Changed
• Emergence of AI agents as primary targets for attacks and insider threats.
• Machine-to-machine connections via MCP introduce new high-risk access paths.
• Data security returns as a frontline challenge due to AI’s ability to surface buried information instantly.
Timelines
Released on 05 January 2026
SailPoint Announces Integrations with the CrowdStrike Falcon Platform
Why This Matters
• Brings identity context into security operations so teams can see who is involved, what access is affected, and respond faster to identity-based threats.
• Enables shared data and automated workflows between identity governance and threat detection/response to improve visibility and speed up remediation.
What Has Changed
• New integrations between SailPoint Identity Security Cloud and the CrowdStrike Falcon® platform to connect identity and threat data.
• Integrates with Falcon Next-Gen Identity Security, Falcon Next-Gen SIEM, and Falcon Fusion SOAR (part of CrowdStrike Charlotte AI).
• Allows customers to:
– Apply CrowdStrike identity risk insights in SailPoint for dynamic, risk-based access decisions.
– Ingest SailPoint identity data into Falcon Next-Gen SIEM to correlate identity/access patterns with real-time threat activity.
– Trigger SailPoint remediation actions via Falcon Fusion SOAR (e.g., disabling accounts or revoking access) to accelerate response.
Timelines
Released on 18 December 2025
ZSP for Entra groups is now available
ZSP for Entra Groups allows for dynamic and temporary assignment of users to Entra groups within your Microsoft Entra ID directories. This means users can be granted access to specific M365 services or applications only when they need it, and for a limited time, without the need to manage the different roles in the ZSP policy.
"Secure Cloud Access and it's new Zero Standing Privilege (ZSP) feature for Entra Groups allows for dynamic and temporary assignment of users to Entra groups within Microsoft Entra ID directories. This means users can be granted access to specific M365 services or applications only when they need it, and for a limited time, without the need to manage the different roles in the ZSP policy."
CyberArk: CA25-35 - Possible race condition that may lead to denial of service (DoS) by unauthenticated users.
Issued: October 29, 2025
Updated: N/A
Version: 1.0
Severity: High
CVSS Score: 8.7
Third-party publication / CVE: N/A
Impact: Possible race condition that may lead to denial of service (DoS) by unauthenticated users.
Affected Products And Versions: Privileged Session Manager for SSH (PSMP), Self-Hosted - All versions prior to version 14.6.1 - All product subsets are affected
Resolution:
Upgrade to a patch version from the table below by downloading the patch from the respective link and following the instructions in our online documentation.
If a patch isn't available for your installed version, or if you want to move to the latest available version, upgrade your component according to the upgrade version compatibility docs.
PSM for SSH 14.6 (LTS) and its patches prior to 14.6.1 - Patch to version 14.6.1 - Download patch - Documentation
PSM for SSH 14.2 (LTS) and its patches prior to 14.2.3 - Patch to version 14.2.3 - Download patch - Documentation
Temporary Mitigation:
There is no temporary mitigation available for this security bulletin.
Read more
CyberArk: CA25-34 - Possible Denial of Service (DoS) attack on HTML5 Gateway server
Issued: October 29, 2025
Updated: N/A
Version: 1.0
Severity: High
CVSS Score: 8.1
Third-party publication / CVE: https://nvd.nist.gov/vuln/detail/CVE-2025-50106 (https://nvd.nist.gov/vuln/detail/CVE-2025-50106)
https://nvd.nist.gov/vuln/detail/cve-2024-30172 (https://nvd.nist.gov/vuln/detail/cve-2024-30172)
Impact: Possible Denial of Service (DoS) attack on HTML5 Gateway server
Affected Products And Versions:
HTML5 Gateway Container and RPM, Self-Hosted - All versions prior to version 14.6 (incl.) - All product subsets are affected
Resolution:
Upgrade to a patch version from the table below by downloading the patch from the respective link and following the instructions in our online documentation.
If a patch isn't available for your installed version, or if you want to move to the latest available version, upgrade your component according to the upgrade version compatibility docs.
Version 14.6 - Patch to version 14.6.1 - Download patch - Documentation
Version 14.2 - Patch to version 14.2.2 - Download patch - Documentation
Version 14.0 - Patch to version 14.0.2 - Download patch - Documentation
Temporary Mitigation:
There is no temporary mitigation available for this security bulletin.
Read more
CyberArk: CA25-33 - Possible DoS attack by locking application users
Issued: October 8, 2025
Updated: N/A
Version: 1.0
Severity: High
CVSS Score: 8.2
Third-party publication / CVE: N/A
Impact: Possible DoS attack by locking application users
Affected products and versions:
Vault Self-Hosted - All versions
* This Security Bulletin applies only to the listed affected products. If this issue also affects another CyberArk product, it will be addressed separately in accordance with CyberArk's Product Vulnerability Management Policy.
** Relates only to versions that are within their development life cycle. Please refer to our End of Life policy for details.
Resolution
Upgrade to a patch version from the following table by downloading the patch from the respective link and following the instructions in our online documentation.
If a patch isn't available for your installed version, or if you want to move to the latest available version, upgrade your component according to the upgrade version compatibility documentation.
Installed Version:
Vault 14.6 and its patches prior to 14.6.2 - Patch version 14.6.2 - https://www.cyberark.com/CA25-33-VaultSH-14.6.2 - docs
Vault 14.2 and its patches prior to 14.2.4 - Patch version 14.2.4 - https://www.cyberark.com/CA25-33-VaultSH-14.2.4 - docs
Vault 14.0 and its patches prior to 14.0.5 - Patch version 14.0.5 - https://www.cyberark.com/CA25-33-VaultSH-14.0.5 - docs
CyberArk recommends enforcing strong password complexity requirements for all system accounts, including both human and non-human users. For detailed settings, please refer to the passparm.ini configuration file.
PAM on Cloud customers: CyberArk will not release AWS AMIs and Azure VM Images. Customers should run the upgrade process on the provided images following deployment.
Temporary mitigation
There is no temporary mitigation available for this security bulletin.
Exploited in the wild in a CyberArk environment
Not to the best of CyberArk’s knowledge.
Technical FAQ
Do I need to upgrade my Disaster Recovery Vault, PAReplicate, and EVD as well?
Disaster Recovery Vault and EVD versions (and patch version) need to be aligned with the Vault's patch version.
PAReplicate should be the same minor version as the Vault (for example, PAReplicate 14.2 is compatible with Vault 14.2.2).
As CyberArk receives questions related to this Security Bulletin, answers will be added to the Technical FAQ article. To stay informed of updates, open the FAQ article and click Follow to receive notifications when new questions and answers are published.
Read more
CyberArk: CA25-32 - Potential disclosure of sensitive information in Central Credential Provider (CCP).
Issued: October 8, 2025
Updated: N/A
Version: 1.0
Severity: High
CVSS Score: 7.1
Third-party publication / CVE: N/A
Impact: Potential disclosure of sensitive information in Central Credential Provider (CCP).
Affected products and versions:
Central Credential Provider (CCP) - Versions 14.0 and 14.2 - Versions prior to 14.0 are not affected
* This Security Bulletin applies only to the listed affected products. If this issue also affects another CyberArk product, it will be addressed separately in accordance with CyberArk's Product Vulnerability Management Policy.
** Relates only to versions that are within their development life cycle. Refer to our End of Life policy for details.
Resolution
Upgrade to a patch version from the following table by downloading the patch from the respective link and following the instructions in our online documentation.
If a patch isn't available for your installed version, or if you want to move to the latest available version, upgrade your component according to the upgrade version compatibility documentation.
Installed Version:
14.0, 14.2, and their patches prior to 14.2.4 - Patch Version 14.2.4 - https://www.cyberark.com/CA25-32-CCP-14.2.4 - Upgrade the Central Credential Provider(CCP) Note: Ensure that you upgrade the CCP's Credential Provider (CP).
Temporary mitigation
There is no temporary mitigation available for this security bulletin.
Exploited in the wild in a CyberArk environment
Not to the best of CyberArk’s knowledge.
Technical FAQ
Are Credential Provider (CP) and Application Server Credential Provider (ASCP) also affected by this issue?
Yes. Credential Provider versions 14.0 and 14.2, including all patches prior to version 14.2.4, are affected by this issue. However, due to the limited attack vector, it is scored as medium severity and does not merit a bulletin announcement. The Application Server Credential Provider relies on the Credential Provider and is therefore also impacted by this issue (at medium severity).
A fix is available in Credential Provider version 14.2.4: https://www.cyberark.com/CA25-32- CP-14.2.4.
As CyberArk receives questions related to this Security Bulletin, answers will be added to the Technical FAQ article. To stay informed of updates, open the FAQ article and click Follow to receive notifications when new questions and answers are published.
Read more
SailPoint Introduces: Agent Identity Security
Why This Matters
As AI agents become integral members of the workforce, organizations need a way to govern and secure them just like human identities.
Agent Identity Security helps enterprises:
- Discover, secure, and govern AI agents under one unified control plane
- Assign ownership and ensure accountability for every agent
- Prevent over-permissioning, misalignment, and regulatory exposure
What Has Changed
Agent Identity Security extends SailPoint’s Identity Security Cloud to include AI agents alongside human users.
Key capabilities include:
- AI Agent Aggregation & Identity Creation – Connect directly to AWS, Azure, and GCP to onboard AI agents with enriched identity context
- Ownership & Succession Planning – Assign human owners to agents and maintain continuous oversight
- Certification & Review – Recertify agent access regularly and revoke inappropriate permissions
- Tool Governance – Apply consistent policies to agent service accounts from creation through retirement
- Audit & Traceability – Maintain full audit trails and certification records for compliance and investigations
Available for: Business and Business+ customers as an add-on capability
CyberArk: Database discovery and automated onboarding
We’re excited to announce a new capability in our discovery SaaS, which extends support to databases. This enhancement enables teams to seamlessly uncover, secure, and onboard database accounts with greater efficiency. Security teams can now accelerate onboarding at scale, reduce manual effort, and ensure database credentials are continuously rotated and tightly controlled.
Key highlights:
- Targeted scanning: Run discovery scans using a CSV list of targets containing access details.
- Dynamic credential utilization: The scan automatically fetches relevant vaulted credentials at runtime, based on target data.
- Centralized discovery flow: Accounts identified during scans are routed into the Discovered Accounts area, making it simple to review and vault them together with other discoveries.
- Automated remediation rules: Define onboarding rules to automatically vault and manage discovered accounts.
- End-to-end coverage: From discovery → onboarding → rotation and access services, database accounts are fully managed in one streamlined workflow.
Supported databases:
- MS SQL Server
- Oracle
- MySQL
- PostgreSQL
Okta: introduces new capability: the Okta MCP Server
Why This Matters
- Lets AI agents interact directly with Okta using natural language
- Reduces the need for manual API calls or custom scripts
- Enables automation of tasks like adding users, managing groups, and generating reports
What Has Changed
- MCP Server bridges AI models with Okta’s Admin APIs
- Supports both interactive login and secure headless authentication (private key JWT)
- Built on Okta’s official SDK for reliability and tight integration
Timelines
- Released: September 22, 2025
- Available now on https://developer.okta.com/blog/2025/09/22/okta-mcp-server
SailPoint: MCP (Model Context Protocol) Server update
SailPoint has just introduced the MCP (Model Context Protocol) Server, and this could be a game changer for how we handle access requests. In short, the MCP Server acts as a standardised bridge between AI applications and SailPoint’s Identity Security Cloud (ISC). Instead of needing heavy custom integration or multiple request centers, it gives you a ready-made interface to connect AI tools directly into SailPoint. That means access requests can finally become as simple as asking an assistant in plain language, without dropping enterprise security standards.
Key Benefits:
- Quick Integration: quickly connect AI applications to SailPoint in 5-15 minutes without complex custom development.
- Natural Language Processing: Enable conversational access request at scale.
- Future-Proof Architecture: Built on MCP standard and regular updates to ensure compatibility with emerging AI platforms and security.
- Enterprise-grade: Maintains SailPoint’s proven IAM expertise and enterprise-grade scalability and security.
Getting Started:
- SailPoint Identity Security Cloud access is required.
- Choose integration approach based on technical requirements.
- Setup authentication following provided guides (coming soon).
- Begin building AI-powered access management experiences
Important Dates:
- General Availability: Sept 29, 2025
- Integration Documentation: Sept 29, 2025
- Expanded Toolkit: 6-12 months post-GA for expanded MCP tools
Dive Deeper
Read more
CyberArk: CA25-31 - Potential authenticated remote code execution.
Issued: September 10, 2025
Updated: N/A
Version: 1.0
Severity: High
CVSS Score: 8.7
Third-party publication / CVE: N/A
Impact: Potential authenticated remote code execution.
Affected products and versions:
Secrets Manager - Self-Hosted (formerly Conjur Enterprise) - 13.5.0 - 13.5.2- 13.6.0 - 13.6.2
* This Security Bulletin applies only to the listed affected products. If this issue also affects another CyberArk product, it will be addressed separately in accordance with CyberArk's Product Vulnerability Management Policy.
** Relates only to versions that are within their development life cycle. Refer to our End of Life policy for details.
Resolution
Upgrade to a patch version from the table below by downloading the patch from the respective link and following the instructions in our online documentation.
If a patch isn't available for your installed version, or if you want to move to the latest available version, upgrade your component according to the upgrade version compatibility docs.
Installed version:
Secrets Manager - Self-Hosted (Conjur Enterprise) prior to 13.6.3 - Patch version 13.6.3 - Documentation
Secrets Manager - Self-Hosted (Conjur Enterprise) 13.5 and its patches prior to 13.5.3 - Patch version 13.5.3 - Documentation
Temporary mitigation
There is no temporary mitigation available for this security bulletin.
Exploited in the wild in a CyberArk environment
Not to the best of CyberArk’s knowledge.
Technical FAQ
Are there any pre-upgrading steps that should be carried out before upgrading?
- Backup your current environment.
- Verify the minimum requirements for Conjur Enterprise and Vault Synchronizer.
- Review the deployment workflow to ensure the usage of the relevant commands needed.
As CyberArk receives questions related to this Security Bulletin, answers will be added to the Technical FAQ article. To stay informed of updates, open the FAQ article and click the Follow button to receive notifications when new questions and answers are published.
SailPoint: A new capability in Identity Security Cloud
SailPoint has introduced a new capability in Identity Security Cloud: the option to automatically delete accounts when an identity is terminated
Why This Matters
- Many customers need more than just disabling accounts
- Until now, this required custom rules (BeforeProvisioning), which slowed projects and added overhead
What Has Changed
- Admins can now configure Lifecycle States to delete accounts (not just enable/disable)
- All deletes are audited, so you know who did what, when, and on which system
- For disconnected systems, SailPoint creates a manual task and sends a notification
Timelines
- Sandbox rollout: Sept 15, 2025
- Production rollout: Week of Sept 22, 2025
CyberArk: CA25-30 - Possible stack overflow that can lead to denial of service (DoS).
Issued: September 3, 2025
Updated: N/A
Version: 1.0
Severity: High
CVSS Score: 7
Third-party publication / CVE:
CVE-2025-48924</a >
Impact: Possible stack overflow that can lead to denial of service (DoS).
Affected products and versions:
z/OS Credential Provider All versions prior to version 14.2
Resolution:
Upgrade to a patch version from the table below by downloading the patch from the respective link and following the instructions in our online documentation.
If a patch isn't available for your installed version, or if you want to move to the latest available version, upgrade your component according to the upgrade version compatibility docs.
Installed version:
z/OS Credential Provider (Java Provider) 14.2 (LTS) and its patches prior to 14.2.3 - Patch version: 14.2.3 -
z/OS Credential Provider (Java Provider) 12.6 (LTS) and its patches prior to 12.6.6 or earlier versions - Patch version: 12.6.6
Temporary mitigation:
There is no temporary mitigation available for this security bulletin.
Read more
CyberArk: CA25-29 - Potential exposure to Prototype Pollution as described in the above third-party CVE
Issued: August 27, 2025
Updated: N/A
Version: 1.0
Severity: High
CVSS Score: 7.8
Third-party publication / CVE: CVE-2024-38996
Impact: Potential exposure to Prototype Pollution as described in the above third-party CVE.
Affected products and versions:
Password Vault Web Access (PVWA) Self-Hosted: All versions earlier than 14.2.4 - All product subsets are affected.
* This Security Bulletin applies only to the listed affected products. If this issue also affects another CyberArk product, it will be addressed separately in accordance with CyberArk's Product Vulnerability Management Policy.
** Relates only to versions that are within their development life cycle. Refer to our End of Life policy for details.
Resolution:
Upgrade to a patch version from the table below by downloading the patch from the respective link and following the instructions in our online documentation.
If a patch isn't available for your installed version, or if you want to move to the latest available version, upgrade your component according to the upgrade version compatibility docs.
PAM On Cloud customers:
- Version 14.2 and later: Download and deploy the patched image from the Marketplace for your deployed solution:
- Versions earlier than 14.2: Follow the instructions for on-premises patches for your deployed version.
Temporary mitigation:
There is no temporary mitigation available for this security bulletin.
Exploited in the wild in a CyberArk environment:
Not to the best of CyberArk’s knowledge.
Read more
SailPoint Identity Security Cloud - New Updates
Key Highlights from this latest release:
- BeyondTrust Password Safe On-Premise Integration: Identity Security Cloud now supports the BeyondTrust Password Safe (On-Premise) credential provider for Secrets Management. This enables credential cycling directly from BeyondTrust, providing stronger security and streamlined password management
- Workflows - Execution Playback:
A new execution playback feature has been introduced for Workflows. Administrators can now “playback” workflow execution logs in the same format as Test Workflow, viewing input/output data step by step. Even if the workflow has been modified since execution, playback restores the original configuration for accurate review and troubleshooting
For the full release notes, visit: https://community.sailpoint.com/t5/SaaS-Release-Notes/tkb-p/saas-release-notes
CyberArk: CA25-28 - Potential session hijacking, allowing unauthorized access to an authenticated Secure Infrastructure Access (SIA) user's session
Issued: August 06, 2025
Updated: N/A
Version: 1.0
Severity: High
CVSS Score: 8.1
Third-party publication / CVE: N/A
Impact: Potential session hijacking, allowing unauthorized access to an authenticated Secure Infrastructure Access (SIA) user's session.
Affected products and versions:
- Secure Infrastructure Access: The following SIA connection types are affected when accessed by users authenticated via a federated identity provider (external IdP):SIA-RDPSIA-SSH
* This Security Bulletin applies only to the listed affected products. If this issue also affects another CyberArk product, it will be addressed separately in accordance with CyberArk's Product Vulnerability Management Policy.
** Relates only to versions that are within their development life cycle. Refer to our End of Life policy for details.
Resolution: To address this, connections via Secure Infrastructure Access (SIA) now include an additional, optional authentication factor.
After the initial authentication step, users will be prompted to enter a PIN code in the native client, as part of the SIA authentication flow.
To enable the additional authentication factor, follow the steps below:
- Log in to the Identity Administration portal.
- Navigate to: Core Services → Policies
- Choose an existing policy to edit or click Add Policy Set to create a new one.
- Navigate to: Authentication Policies → CyberArk Identity Security Platform
- Set the drop-down menu Enable authentication policy controls to Yes.
- Check the box for Enable PIN code protection for native clients.
- Click Save.
It's important to note that even if the flag is already enabled, you still need to click 'Save' for the new flow to apply.
Temporary mitigation:
There is no temporary mitigation available for this security bulletin.
Read more
BeyondTrust: CVE-2025-2297 & CVE-2025-6250
We would like to inform you about two recently published high severity vulnerabilities in Privilege Management for Windows.
Summary
· CVE-2025-2297: This high severity vulnerability in Privilege Management for Windows allows for a local authenticated attacker to elevate privileges.
· CVE-2025-6250: This high severity vulnerability in Privilege Management for Windows allows for a local authenticated attacker with elevated privileges to bypass anti-tamper protections.
Who May Be Impacted
Privilege Management for Windows customers on the versions prior to 25.4.270.0
Resolution and Mitigation
Both vulnerabilities have been addressed in Privilege Management for Windows 25.4.270.0. At the time of the CVE's release on July 28th, all cloud tenants will have been upgraded to 25.4. Customers can push version 25.4.270.0 to clients to remediate this vulnerability.
Want to dive deeper? Check it out here:
Read more
SailPoint: Identity Security Cloud Production release notes
Product and Feature enchacements:
Machine Identity Security:
- Users can now opt out of the Machine Account Discovery feature by disabling it on the System Features page.
Connectivity - Jack Henry:
- The Jack Henry connector now supports Symitar 2024.
Connectivity - Snowflake:
- The Snowflake Connector can now aggregate database roles as entitlements. It can also assign and revoke database roles at the account level.
Identity Security Cloud - Core Access Model:
- Standard criteria for role assignments have been enhanced as follows to provide an improved administrative experience and greater flexibility in assigning roles:
- A Does Not Contain operator has been added for Identity and Account attribute expressions.
- The ability to compare against a list of values in a single criteria statement has been added. For example, you could evaluate if a user’s department is EQUAL to Accounting, Finance, or Accounts Payable in a single statement.
- The >, >=, <, and <= numeric operations have been added to account attribute expressions.
- Issues with boolean comparisons evaluating null values as FALSE have been resolved.
Fixes:
Identity Security Cloud - Core Access Model (SAASTRIAGE-8724):
- Fixed an issue where source attributes were not displaying on the Entitlement Details page.
Connectivity - Active Directory(CONETN-5109):
- The Active Directory connector no longer throws an error when using a gMSA account if the same service account is being used for multi-domain or multi-forest configurations.
Further details available from the Compass Community site here: SaaS Release Notes - Compass
CyberArk: CA25-27 - Potential authentication bypass via Identity connector synchronization
Issued: July 15, 2025
Updated: N/A
Version: 1.0
Severity: High
CVSS Score: 8.3
Third-party publication / CVE: N/A
Impact: Potential authentication bypass via Identity connector synchronization
Product:
- SSH Manager for Machines (formerly known as SSH Protect) - All versions prior to version 25.1
- Code Signing Manager (formerly known as CodeSign Protect) - All versions prior to version 25.1
- Certificate Manager, Self-Hosted (formerly known as TLS Protect Datacenter) - All versions prior to version 25.1
* This security bulletin applies only to the listed affected products. If this issue also affects another CyberArk product, it will be addressed in a separate security bulletin.
** Relates only to versions that are within their development life. Please refer to our End-of-Life policy for details
Resolution
Upgrade to a patch version by downloading the patch from the respective link and following the instructions in our online documentation.
If a patch isn't available for your installed version, or if you want to move to the latest available version, upgrade your component according to the upgrade version compatibility docs.
Want to dive deeper? Check it out here
Read more
CyberArk: CA25-26 - Potential disclosure of sensitive information to users with administrative privileges
Issued: July 15, 2025
Updated: N/A
Version: 1.0
Severity: High
CVSS Score: 7.2
Third-party publication / CVE: N/A
Impact: Potential disclosure of sensitive information to users with administrative privileges
- Certificate Manager, Self-Hosted (formerly TLS Protect Datacenter) - All versions prior to version 25.1
- SSH Manager for Machines (formerly SSH Protect) - All versions prior to version 25.1
- Code Sign Manager (formerly CodeSign Protect) - All versions prior to version 25.1
* This Security Bulletin applies only to the listed affected products. If this issue also affects another CyberArk product, it will be addressed separately in accordance with CyberArk's Product Vulnerability Management Policy.
** Relates only to versions that are within their development life cycle. Refer to our End of Life policy for details.
Resolution:
Upgrade to a patch version by downloading the patch from the respective link and following the instructions in our online documentation.
Want to dive deeper? Check it out here
Read more
CyberArk: CA25-25 - Potential excessive consumption of resources on the host system that can lead to a denial of service (DoS)
Issued: July 15, 2025
Updated: N/A
Version: 1.0
Severity: High
CVSS Score: 8.7
Third-party publication / CVE: CVE-2025-30204
Impact: Potential excessive consumption of resources on the host system that can lead to a denial of service (DoS)
Affected products and versions
- Secrets Manager, SaaS (formerly Conjur Cloud) Edge - All versions prior to version 15.0
* This security bulletin applies only to the listed affected products. If this issue also affects another CyberArk product, it will be addressed separately in accordance with CyberArk's Product Vulnerability Management Policy.
** Relates only to versions that are within their development life. Please refer to our End-of-Life policy for details
Resolution
Upgrade to a version by downloading the version from the respective link and following the instructions in our online documentation.
Want to dive deeper? Check it out here
Read more
SailPoint: IdentityIQ 8.5 New Features
New Features:
Microsoft Teams Integration: Access Request Approvals:
- With this enhancement to IdentityIQ's Microsoft Teams integration, approvers now have a simple way to manage access request approvals that is seamlessly integrated with Microsoft Teams, enabling them to make decisions on the go. Here are few of the actions users can take:Accept, Deny, Forward, AssignView work item detailsView policy violations
GenAI Descriptions for Entitlements:
- Managing entitlement descriptions at scale can be overwhelming—some IdentityIQ customers have catalogs with over a million entitlements. To ease this burden, IdentityIQ 8.5 introduces a powerful new GenAI-driven feature that automatically suggests entitlement descriptions using large language models. This enhancement helps keep your catalog accurate and up-to-date with minimal effort, saving time and improving clarity across your identity landscape.
Restrict View of Sensitive Identity Attributes:
- As organizations store more sensitive personal data in IdentityIQ, protecting that information is more important than ever. With IdentityIQ 8.5, we’re introducing the ability to restrict visibility of sensitive identity attributes—ensuring that only users with a legitimate purpose can access certain personal or confidential fields. Whether it's PII or other sensitive identity data, this feature allows you to define exactly who can see what, with flexible configuration options.
This enhancement helps organizations enforce data privacy while still empowering users to do their jobs effectively. Affected areas include Identity Warehouse, Manage Identity, Access Reviews, and Work Items.
UX/UI Modernization and Improvements:
- As part of our continued effort to modernize IdentityIQ and improve the user experience, IdentityIQ 8.5 includes several UI and UX enhancements:
- Improved the Sunrise/Sunset experience with a more intuitive look and feel, and a streamlined flow for adding, removing, or changing access. In addition, the terms Sunrise/Sunset Dates have been renamed to Start/End dates for better clarity.
- Added new filters, Role Owner and Access Type, on the Manage Access Request page to help users find relevant access more efficiently.
- Enhanced the end user access review page by making sorting clearer and displaying the actual due date directly in the UI.
- Made the “Show Classifications” option configurable in Entitlement Owner Certifications, allowing more flexibility based on certification needs.
- Modernized the front-end framework from AngularJS to Angular 18 on the following pages:
- Access Review
- Rapid Setup
- Login Page
- Admin Preferences
- API Authentication
- Access History
Access Request Entitlement Recommendations (Coming Soon):
- Access Request Recommendations have been expanded to include entitlements, enhancing the self-service experience with intelligent, data-driven recommendations. This improvement helps users request appropriate access more efficiently and reduces the burden on approvers by minimizing unnecessary or inappropriate requests.This feature closes the gap between role and entitlement recommendations by offering both options for self-service access requests. Recommendations eliminate guesswork by suggesting the entitlements users need to perform their job and consolidating all required access into a single request.
Further details available from the Compass Community site here: What's New in IdentityIQ 8.5 - Compass
Read more
CyberArk: CA25-24 - Potential disclosure of sensitive information as part of the PTA DR setup
Issued: July 2, 2025
Updated: N/A
Version: 1.0
Severity: High
CVSS Score: N/A
Third-party publication / CVE: N/A
Impact: Potential disclosure of sensitive information as part of the PTA DR setup
Affected products and versions:
- Privileged Threat Analytics, Self-Hosted - All versions prior to 14.6
* This Security Bulletin applies only to the listed affected products. If this issue also affects another CyberArk product, it will be addressed separately in accordance with CyberArk's Product Vulnerability Management Policy.
** Relates only to versions that are within their development life cycle. Refer to our End of Life policy for details.
Resolution:
Upgrade to a patch version by downloading the patch from the respective link and following the instructions in our online documentation.
If a patch isn't available for your installed version, or if you want to move to the latest available version, upgrade your component according to the upgrade version compatibility docs.
Want to dive deeper? Check it out here
Read more
CyberArk: CA25-23 - Potential MongoDB Shell Control Character Injection
Issued: July 2, 2025
Updated: N/A
Version: 1.0
Severity: High
CVSS Score: 7.2
Third-party publication / CVE: CVE-2025-1691
Impact: Potential MongoDB Shell Control Character Injection
Affected products and versions:
- Privileged Threat Analytics, Self-Hosted - All versions prior to 14.6
* This Security Bulletin applies only to the listed affected products. If this issue also affects another CyberArk product, it will be addressed separately in accordance with CyberArk's Product Vulnerability Management Policy.
** Relates only to versions that are within their development life cycle. Refer to our End of Life policy for details.
Resolution:
Upgrade to a patch version by downloading the patch from the respective link and following the instructions in our online documentation.
If a patch isn't available for your installed version, or if you want to move to the latest available version, upgrade your component according to the upgrade version compatibility docs.
Want to dive deeper? Check it out here
Read more