PatchSiren

SEP CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW SEP CVE published 2026-09-12

CVE-2026-79300

CVE-2026-79300 SEP sesam MFA Weakness. SEP sesam before 5.2.0.24 mishandles User Authorization with MFA when AD authentication is configured. The difference in username capitalization handling between SEP sesam and Active Directory may allow multiple SEP sesam user accounts to be created for the same AD account. This could potentially allow an additional OTP Authenticator to be registered for the same AD [truncated]