PatchDayAlert

CVE

CVE-2026-12263

0field notes · 1digest CVSS 8.8

The verdict

An attacker can bypass authentication entirely in ManageEngine Password Manager Pro and PAM360 by exploiting broken SAML validation. No credentials needed. Given that these products literally store every privileged credential in your environment, a bypass here is about as bad as it gets.

Patch urgency · Patch immediately


Daily digests