Appliance, CI, and control-plane auth CVEs
RMM, VPN, CI, print, and mail admin planes keep failing authentication. They are identity products whether the IAM team owns them or not.
How this protocol fails
ScreenConnect, TeamCity, PaperCut, N-able N-central, Ivanti EPMM/Sentry/Connect Secure, Citrix Bleed, Outlook NTLM, Zimbra MFA backup codes, SmarterMail, Check Point hash leaks, BeyondTrust PRA. The pattern is an internet-facing management login, an alternate path, and ransomware or a state actor three days later. CISA KEV is concentrated here. Incomplete first fixes (N-central, FortiCloud SSO, TeamCity sequels) are how the same incident lasts a year.
What security people should do
- Patch KEV items on internet-facing admin planes first. Confirm the build string, not the calendar date of the last change window.
- If the box was reachable at disclosure, rebuild and rotate. A hotfix on a planted admin is not eviction.
- Take management UIs off the internet. Put them behind phishing-resistant MFA and a jump path.
- Hunt for rogue admins, unexpected tunnels, and sessions with no matching interactive login.
CVEs in this category
Showing 27 of 27
- CVE-2026-18577criticalCISA KEVExploitedN-able N-central auth bypass, incomplete patch of CVE-2026-18556N-able N-central · N-able · 2026-08-03 · Actively exploited
N-able N-central authentication bypass and account takeover. The first fix (CVE-2026-18556) was incomplete. Actively exploited. CISA added it to KEV on 3 August 2026.
- CVE-2026-63077criticalTeamCity agent-polling protocol authentication bypass to RCEJetBrains TeamCity On-Premises · JetBrains · 2026-07-27 · Patched
Every on-premises TeamCity version was vulnerable. An unauthenticated attacker abuses the agent polling channel and runs OS commands as the server. Fixed 27 July 2026. The third TeamCity auth-bypass in this catalog.
- CVE-2025-66376criticalCISA KEVExploitedZimbra ZCS chained with CVE-2025-48700 to steal MFA backup codesZimbra Collaboration Suite · Synacor / Zimbra · 2026-03-15 · Actively exploited
Zimbra Collaboration Suite, chained with CVE-2025-48700, was used to steal MFA backup codes and app passwords (CERT-UA UAC-0233). Added to CISA KEV in mid-March 2026.
- CVE-2026-23760criticalCISA KEVExploitedSmarterMail auth bypass via an alternate path, CISA KEVSmarterMail · SmarterTools · 2026-01-15 · Actively exploited
SmarterMail accepted authentication on an alternate path. CISA KEV, January 2026. Mail-admin planes keep failing the 'we protected the primary URL' test.
- CVE-2025-67505high 8.4Okta Java SDK race condition crosses responses between requestsOkta Java SDK · Okta · 2025-12-11 · Patched
The Okta Java SDK could attach another request's response to yours (CWE-362). CVSS 8.4. Patched in v20.0.1, December 2025. Token mix-up in the official SDK.
- CVE-2025-13881highKeycloak Admin API auth bypass to custom attributesKeycloak · Red Hat · 2025-11-20 · Patched
Keycloak's Admin API let a caller read sensitive custom attributes they should not have seen (CWE-266). An authorization hole on the admin plane.
- CVE-2025-64446critical 9.8CISA KEVExploitedFortiWeb auth bypass and path traversal, admin creationFortinet FortiWeb · Fortinet · 2025-11-14 · Actively exploited
FortiWeb authentication bypass plus path traversal that lets an attacker create an admin. CVSS 9.8. Added to CISA KEV around 14 November 2025, before the December FortiCloud SSO wave.
- CVE-2025-59280highWindows SMB Client improper authentication (tampering)Windows SMB Client · Microsoft · 2025-10-14 · Patched
Windows SMB Client improper authentication (CWE-287) that allows tampering. Not an Entra token bug, but it sits in the same Microsoft identity-adjacent patch train as the 2025 Kerberos work.
- CVE-2025-11419mediumKeycloak TLS 1.2 renegotiation denial of serviceKeycloak · Red Hat · 2025-10-08 · Patched
Keycloak could be knocked over by TLS 1.2 renegotiation. Availability of the IdP is an identity incident. Not an auth bypass.
- CVE-2025-55129criticalIvanti EPMM addUser validation bypass and impersonationIvanti Endpoint Manager Mobile (EPMM) · Ivanti · 2025-08-19 · Patched
Ivanti Endpoint Manager Mobile failed to validate addUser. An attacker can create or impersonate a user. Mobile-device management is an identity control plane.
- CVE-2025-32975criticalCISA KEVExploitedQuest KACE SMA improper authentication, CISA KEVQuest KACE Systems Management Appliance · Quest · 2025-04-02 · Actively exploited
Quest KACE Systems Management Appliance improper authentication. On CISA KEV. A management appliance with a broken login is a fleet-wide identity incident.
- CVE-2025-20059critical 9.2PingAM Java Policy Agent path traversal and parameter injectionPingAM Java Policy Agent · Ping Identity · 2025-02-12 · Patched
PingAM Java Policy Agent allowed relative path traversal and parameter injection. CNA CVSS-B 9.2. February 2025. A policy-agent bug is an authz bypass in front of every app it protects.
- CVE-2025-0604highKeycloak password reset skips re-validation against ADKeycloak · Red Hat · 2025-01-22 · Patched
Keycloak did not re-check Active Directory on password reset. An expired or disabled AD account could regain access through Keycloak's reset flow.
- CVE-2024-12356critical 9.8CISA KEVExploitedBeyondTrust PRA and Remote Support unauthenticated command injectionBeyondTrust Privileged Remote Access / Remote Support · BeyondTrust · 2024-12-16 · Actively exploited
Privileged Remote Access and Remote Support accepted a malicious client request and ran OS commands as the site user. Unauthenticated. CVSS 9.8. CISA KEV. A PAM control-plane bug, not a random RCE.
- CVE-2024-7061highOkta Verify for Windows local privilege escalationOkta Verify for Windows · Okta · 2024-07-23 · Patched
Okta Verify on Windows could be turned into a local privilege escalation. The MFA app on the endpoint is part of the identity plane. Pair with Okta's 2024 FastPass phishing research and the 52-character DelAuth advisory, which did not get a CVE.
- CVE-2024-24919criticalCISA KEVExploitedCheck Point Security Gateway information disclosure of password hashesCheck Point Security Gateway · Check Point · 2024-05-28 · Actively exploited
An unauthenticated read on Check Point Security Gateways leaked password hashes, including those used for VPN and local admin. CISA KEV. May 2024. Hash disclosure is an identity incident on a VPN concentrator.
- CVE-2023-6544highKeycloak authorization bypassKeycloak · Red Hat · 2024-04-16 · Patched
Keycloak failed an authorization check, so a caller could reach a resource their role should have blocked. Part of the April 2024 RHSA-2024:1868 set with CVE-2023-6787 and CVE-2023-6717.
- CVE-2024-27198critical 9.8CISA KEVExploitedJetBrains TeamCity 2024 authentication bypass, admin accessJetBrains TeamCity On-Premises · JetBrains · 2024-03-04 · Actively exploited
Unauthenticated attacker becomes a TeamCity administrator on on-prem instances. CVSS 9.8. Widely exploited. CISA KEV. The 2024 sequel to CVE-2023-42793, and the reason the 2026 agent-polling bypass was treated as urgent.
- CVE-2024-1709critical 10.0CISA KEVExploitedConnectWise ScreenConnect auth bypass via an alternate pathConnectWise ScreenConnect · ConnectWise · 2024-02-19 · Actively exploited
ScreenConnect 23.9.7 and earlier skipped authentication on an alternate setup path (CWE-288). Attackers created admin users within hours. CISA KEV. CVSS 10.0. Pair with CVE-2024-1708 (path traversal) for the RCE chain.
- CVE-2023-46805criticalCISA KEVExploitedIvanti Connect Secure authentication bypassIvanti Connect Secure / Policy Secure · Ivanti · 2024-01-10 · Actively exploited
Connect Secure and Policy Secure skipped authentication on a path that later chained with CVE-2024-21887 for unauthenticated RCE. CISA KEV. January 2024 disclosure of a 2023 bug. The VPN login was optional.
- CVE-2023-4966critical 9.4CISA KEVExploitedCitrix Bleed, session-token leak from NetScaler ADCCitrix NetScaler ADC / Gateway · Cloud Software Group · 2023-10-10 · Actively exploited
A buffer over-read on NetScaler ADC/Gateway leaked session tokens in the clear. Attackers replayed them and skipped the login, including MFA. CISA KEV. October 2023. The textbook session-hijacking CVE.
- CVE-2023-42793critical 9.8CISA KEVExploitedJetBrains TeamCity 2023 authentication bypass to RCEJetBrains TeamCity On-Premises · JetBrains · 2023-09-19 · Actively exploited
Unauthenticated request becomes administrator, then code execution, on TeamCity On-Premises before 2023.05.4. CVSS 9.8. CISA KEV. Used by Russian state actors. The 2023 original of a three-year TeamCity pattern.
- CVE-2023-38035criticalCISA KEVExploitedIvanti Sentry authentication bypassIvanti Sentry (MobileIron Sentry) · Ivanti · 2023-08-21 · Actively exploited
Ivanti Sentry (MobileIron Sentry) skipped authentication on an administrative API. CISA KEV. August 2023. The gateway in front of EPMM had its own unlocked door.
- CVE-2023-35078criticalCISA KEVExploitedIvanti EPMM (MobileIron Core) unauthenticated API accessIvanti Endpoint Manager Mobile (MobileIron Core) · Ivanti · 2023-07-24 · Actively exploited
Every supported EPMM 11.8-11.10 release exposed restricted API functionality with no login. Attackers pulled user and device data, then chained CVE-2023-35081. CISA KEV. July 2023. MDM is an identity control plane.
- CVE-2023-27351criticalCISA KEVExploitedPaperCut NG/MF improper authentication, still on CISA KEVPaperCut NG/MF · PaperCut · 2023-04-20 · Actively exploited
PaperCut NG/MF improper authentication. A 2023 CVE that remains on CISA KEV and in 2025-2026 ransomware playbooks. Print-management appliances keep getting treated as low-value. They are not.
- CVE-2023-27350criticalCISA KEVExploitedPaperCut NG/MF auth bypass to remote code executionPaperCut NG/MF · PaperCut · 2023-04-20 · Actively exploited
The critical sibling of CVE-2023-27351. Unauthenticated setup path plus built-in scripting became RCE. CISA KEV. Used by ransomware in April-May 2023. Print servers hold AD bind accounts.
- CVE-2023-23397critical 9.8CISA KEVExploitedOutlook reminder leaks Net-NTLMv2 hashes with no clickMicrosoft Outlook for Windows · Microsoft · 2023-03-14 · Actively exploited
A crafted Outlook appointment set PidLidReminderFileParameter to an attacker UNC path. The client leaked NTLM hashes when the reminder fired. No user click. CISA KEV. March 2023. Credential theft as a calendar invite.