CVE-2026-20746 is a MEDIUM severity vulnerability in Ping Identity PingDirectory. The vulnerability allows authorized users to exhaust the Java memory heap when recent login history is enabled and copying virtual attributes that reference ds-privilege-name values. The vulnerability was published on 2026-06-12T04:17:04.510Z and last modified on 2026-06-12T16:06:17.027Z.
CVE-2025-20628 describes an insufficient granularity of access control vulnerability in PingIDM (formerly ForgeRock Identity Management). Administrators cannot properly configure access rules for Remote Connector Servers (RCS) running in client mode, allowing attackers to potentially spoof a client-mode RCS and intercept or modify security-relevant properties. This issue is exploitable only when an RCS is [truncated]