{"record":"Ping Identity evidence record","url":"https://nexalign.io/vendors/ping-identity","vendor":{"slug":"ping-identity","name":"Ping Identity","domain":"pingidentity.com","category":"iam","categoryLabel":"Identity and access management"},"lastChecked":"2026-07-27T16:18:14.884Z","coverage":{"earliest":"2014-12-12T15:00:00.000Z","latest":"2026-07-27T16:18:14.884Z"},"terms":{"isRanking":false,"isRating":false,"statesSuitability":false,"note":"This is a record of what public sources hold about a named company. It states no ranking, no rating and no suitability verdict, and none may be derived from it. An absent or small record means the public registers publish little under that name; it is not evidence that a product is secure. A larger advisory count generally reflects wider deployment and more scrutiny rather than a weaker product.","licence":"https://nexalign.io/vendors#licence","corrections":"info@nexalign.io"},"totals":{"evidenceItems":34,"kindsOfSource":5,"attributedAdvisories":24,"knownExploited":0,"registerEntriesNotAttributable":3,"practitionerThreads":0,"independentItems":4,"vendorPublishedItems":0,"shareFromSourcesTheVendorDoesNotControl":1},"sources":[{"source":"European Vulnerability Database","operator":"ENISA, European Union","classification":"authoritative","items":26,"latest":"2026-06-12T02:16:59.000Z"},{"source":"National Vulnerability Database","operator":"NIST, United States Department of Commerce","classification":"authoritative","items":2,"latest":"2026-06-12T04:17:04.510Z"},{"source":"CERT-Bund security advisories","operator":"BSI, Federal Republic of Germany","classification":"authoritative","items":1,"latest":"2023-03-27T11:09:06.718Z"},{"source":"Analyst, review and reference sources","operator":"Recognised analysts, review marketplaces and technology press","classification":"independent","items":4,"latest":"2026-07-27T16:18:14.884Z"},{"source":"Practitioner discussions","operator":"Reddit, public threads","classification":"independent","items":1,"latest":"2026-02-23T05:16:16.000Z"}],"advisories":{"shown":6,"total":24,"truncated":true,"fullList":"https://nexalign.io/vendors/ping-identity/advisories","items":[{"id":"CVE-2026-20746","description":"Virtual attribute handling in Ping Identity PingDirectory in affected versions allows only authorized users to exhaust java memory heap when recent login history is enabled and copying…","severity":"medium","cvss":6.3,"knownExploited":false,"date":"2026-06-12T04:17:04.510Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2026-20746","https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-36374"]},{"id":"CVE-2025-20628","description":"An insufficient granularity of access control vulnerability exists in PingIDM (formerly ForgeRock Identity Management) where administrators cannot properly configure access rules for Remote…","severity":"medium","cvss":6.9,"knownExploited":false,"date":"2026-04-07T23:16:27.040Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2025-20628","https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-209288"]},{"id":"CVE-2025-27935","description":"The OTP Integration Kit for PingFederate fails to enforce HTTP method validation and state validation properly.","severity":"high","cvss":8.6,"knownExploited":false,"date":"2025-12-04T20:38:31.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-201281"]},{"id":"CVE-2025-26862","description":"Unexpected authentication form rendering in HTML Form Adapter using only non-default redirectless mode in PingFederate allows authentication attempts which may enable brute force login…","severity":null,"cvss":null,"knownExploited":false,"date":"2025-10-27T14:39:41.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-36181"]},{"id":"CVE-2024-25573","description":"Unsanitized user-supplied data saved in the PingFederate Administrative Console could trigger the execution of JavaScript code in subsequent user processing.","severity":"medium","cvss":6.9,"knownExploited":false,"date":"2025-06-15T15:25:38.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-22901"]},{"id":"CVE-2025-22854","description":"Improper handling of non-200 http responses in the PingFederate Google Adapter leads to thread exhaustion under normal usage conditions.","severity":"medium","cvss":6.9,"knownExploited":false,"date":"2025-06-15T15:00:06.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-18340"]}]},"practitionerThreads":{"shown":0,"total":0,"truncated":false,"items":[]},"independentCoverage":{"shown":4,"total":4,"truncated":false,"items":[{"title":"Ping Identity Platform Reviews, Competitors and Pricing","host":"peerspot.com","url":"https://www.peerspot.com/products/ping-identity-platform-reviews","date":null},{"title":"Ping Identity - Wikipedia","host":"en.wikipedia.org","url":"https://en.wikipedia.org/wiki/Ping_Identity","date":null},{"title":"Ping Identity Platform Reviews & Ratings 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/product/ping-identity-platforms","date":null},{"title":"Ping Identity Reviews, Ratings & Features 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/market/access-management/vendor/ping-identity","date":null}]},"vendorPublished":{"shown":0,"total":0,"truncated":false,"items":[]},"openQuestions":["A further 3 register entries mention Ping Identity without naming a product of Ping Identity as affected. They are excluded rather than counted as vulnerabilities.","No public practitioner discussion naming Ping Identity was found in the indexed threads. Operational experience with this product is not represented in this record.","Pricing, contract terms, notice periods and support commitments are not part of any public register. They come from the vendor and belong in a negotiation record.","Certification status such as ISO 27001, SOC 2 or BSI C5 has to be checked against the current certificate and its stated scope. A valid certificate can still exclude the product being bought."]}