CVE-2025-26862EPSS p18.3%

CVE-2025-26862CVE-2025-26862

Description

Unexpected authentication form rendering in HTML Form Adapter using only non-default redirectless mode in PingFederate allows authentication attempts which may enable brute force login attacks.

Scoring

EPSS0.28% probability of exploitation · percentile 18.3% · 2026-10-05T12:00:23Z
Last modified2026-09-30
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.