IdentityBriefing
TopicsIdentity AttacksAI & Agent IdentityAuthenticationStandards & RegulationVendor MovesCommunity & Events

This fortnight

All briefings →
  1. 103 Websites Had Passkeys. None Got Implementation Right

    Louis Jannett's USENIX-award-winning research found 18 critical and 53 high-severity vulnerabilities across 103 real-world passkey deployments. The biggest companies were the worst offenders.

    authentication ·

  2. Microsoft fixes a CVSS 10.0 Entra ID flaw, and nobody has to do anything

    A maximum-severity deserialization bug that could have meant remote code execution, patched on the service side before customers ever saw an action item.

    identity attacks ·

  3. Not one identity leader could count the AI agents running in production

    We surveyed the Identity Leaders Network and ran a roundtable on agent inventory and governance. 40% have no idea how many agents they are running, and 40% say nobody owns the problem.

    community & events ·

  4. Attackers are going after the password reset, not the password

    A critical Keycloak flaw, a Kerberos attack called ResetNightmare and a wave of helpdesk social engineering all point at the same gap: recovery is weaker than the login it replaces.

    identity attacks ·

  5. A security company got socially engineered and published exactly what happened

    A ReliaQuest employee entered their password on a fake SSO page and approved the MFA push. What stopped the attacker was everything sitting behind the login.

    identity attacks ·

  6. OpenAI will sell you a YubiKey now

    A custom two-pack under the Advanced Account Security programme. Hardware-backed passkeys are becoming a consumer product, not a privileged-user control.

    authentication ·

Identity Threat Radar

The full radar →

CISA’s Known Exploited Vulnerabilities catalogue, cut down to the entries where identity was the way in. We group them by how the failure actually happened and add our own notes on the ones worth your time.

Pre-authentication bypass 6

CVE-2026-76460Cisco Identity Services EngineTop 45%

Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.

CISA Apply mitigations in accordance with vendor instructions. Federal deadline 19 Sep 2026.

NVD record for CVE-2026-76460

CVE-2026-76461Cisco Secure Email GatewayTop 20%

Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.

CISA Apply mitigations in accordance with vendor instructions. Federal deadline 17 Sep 2026.

NVD record for CVE-2026-76461

CVE-2026-42018JFrog ArtifactoryTop 4%

JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

CISA Apply mitigations in accordance with vendor instructions. Federal deadline 25 Sep 2026.

NVD record for CVE-2026-42018

CVE-2026-67277MikroTik RouterOSTop 43%

MikroTik RouterOS contains a missing authentication for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service.

CISA Apply mitigations in accordance with vendor instructions. Federal deadline 13 Sep 2026.

NVD record for CVE-2026-67277

CVE-2026-20079Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementTop 1%

Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.

CISA Apply mitigations in accordance with vendor instructions. Federal deadline 12 Sep 2026.

NVD record for CVE-2026-20079

CVE-2026-19490Citrix NetScalerTop 7%

Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication.

CISA Apply mitigations in accordance with vendor instructions. Federal deadline 12 Sep 2026.

NVD record for CVE-2026-19490

Privilege escalation 2

CVE-2026-84869ConnectWise ScreenConnectTop 49%

ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to transfer and execute files through an active remote session without authorization or host confirmation.

CISA Apply mitigations in accordance with vendor instructions. Federal deadline 14 Sep 2026.

NVD record for CVE-2026-84869

CVE-2026-42016JFrog ArtifactoryTop 5%

JFrog Artifactory contains an incorrect authorization vulnerability that leads to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

CISA Apply mitigations in accordance with vendor instructions. Federal deadline 25 Sep 2026.

NVD record for CVE-2026-42016

Catalogue updated 18 Sep 2026 · Likelihood from FIRST’s EPSS. · All 259 identity entries

The fortnightly read for identity practitioners.

Original data from identity leaders, one proper deep dive, and the fortnight's news that actually matters. Free, every two weeks.

Read the latest issue →

Read by identity architects, IAM leads and security leaders across ANZ, the US and the UK.

You're subscribed. Read the latest issue →