Security Advisory Summary: September 2026
Last Updated:
Overview
Okta is committed to transparency and keeping the identity ecosystem secure, which is why we're sharing a confirmed set of vulnerabilities we’ve identified after using advanced AI Frontier models to proactively scan our code as part of our continuous security hardening work.
Applies To
- Okta Access Gateway (OAG)
- Okta Hyperdrive Agent
- Okta Privileged Access (OPA)
- Okta Verify for Windows
Solution
Administrators must perform appropriate version upgrades to maintain a secure environment
Our priority is to help customers quickly find the information that is relevant to them and understand any actions they may need to take. Our monitoring telemetry shows no evidence of exploitation, with discovered vulnerabilities ranging from Medium to High severity (CVSS 4.8–8.1).
Review the security advisories and apply the necessary updates. Each advisory includes specific, actionable guidance so you can take the steps that matter for your organization.
-
Review Okta Security Advisories: Public-facing advisories are the primary source of issue-specific information and guidance.
-
Stay up to date: Check the Okta Security Advisories page regularly for the latest published guidance.
Security Advisories categorized by product
Review the listed categories to find the specific security advisories and corresponding product update links for each product.
Okta Access Gateway (OAG)
- Improper Input Sanitization in Okta Access Gateway Application Label Configuration CVE-2026-78545 - Sep 8, 2026
- Improper Input Handling in Okta Access Gateway Management Console Exception Handler CVE-2026-78550 - Sep 8, 2026
- Improper Handling of SAML Assertion Attributes in Okta Access Gateway Advanced Mode Datastores CVE-2026-78623 - Sep 8, 2026
- Validation Bypass in Okta Access Gateway Custom Directives CVE-2026-78552 - Sep 8, 2026
- Improper Authentication Validation in Okta Access Gateway Pass-Through Authentication Source CVE-2026-78560 - Sep 8, 2026
- Improper Path Validation in Okta Access Gateway Backup and Restore Functionality CVE-2026-78624 - Sep 8, 2026
- Insufficient Validation of Dashboard Application Labels in Okta Access Gateway Dashboard Site Configuration CVE-2026-78625 - Sep 8, 2026
- Improper Input Sanitization in Okta Access Gateway Protected Rules CVE-2026-78626 - Sep 8, 2026
- Improper Input Sanitization in Okta Access Gateway LDAP Datastore Filter Interpolation CVE-2026-78579 - Sep 8, 2026
- Improper Path Validation in Okta Access Gateway Kerberos Configuration Handling CVE-2026-78620 - Sep 8, 2026
- Improper Input Neutralization in Okta Access Gateway SNMP Configuration Processing CVE-78630 - Sep 8, 2026
Okta Hyperdrive Agent
- Improper Restriction of Sensitive Information in Okta Hyperdrive Agent Logging CVE-2026-78631 - Sep 8, 2026
- Improper Authentication Verification in the Okta Hyperdrive Agent MFA Response Handling CVE-2026-78629 - Sep 8, 2026
- Improper Credential Protection in Okta Hyperdrive Integration Installer Logging CVE-2026-78627 - Sep 8, 2026
- Improper Assembly Resolution in Okta Hyperdrive Integration Plugin Registry Handling CVE-2026-78574 - Sep 8, 2026
Okta Privileged Access (OPA)
- Improper Validation of SSH Target in Okta Privileged Access Client CVE-2026-77585 - Aug 25, 2026
- Improper Input Validation in the Okta Privileged Access SSH Client URL Handler Argument CVE-2026-78635 - Sep 8, 2026
Okta Verify for Windows
Why are we sharing this security guidance?
This security guidance reflects our ongoing focus on continuous hardening and proactive vulnerability identification. By providing timely, accessible guidance, we help our customers understand what's relevant to their environments and take action when needed.
We're committed to raising the bar for the identity industry and delivering on the Okta Secure Identity Commitment (OSIC). Security is foundational to identity, and we invest in keeping our products hardened and secure while advancing transparency and stronger security practices across the ecosystem.
Additional resources
- View Okta Security Advisories — Access the Okta Trust Site Security Advisories page for the complete CVE list and applicable updates
- Subscribe to security updates — Follow our Security Advisories via RSS feed to stay current as new guidance is published
- Explore how we found these vulnerabilities — Read our Security Blog article: Hunting Vulnerabilities Using Frontier Models for more on how we used advanced AI capabilities to proactively scan our code, and the key lessons we learned
- Learn more about the Okta Secure Identity Commitment (OSIC) — Understand our ongoing commitment to transparency and continuous hardening
- We’re here to help — For additional assistance, contact us by using the Okta Support Center.
