<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Security Advisory Summary: September 2026

Access Gateway
Okta Verify
Privileged Access
Additional Resources

Overview

Okta is committed to transparency and keeping the identity ecosystem secure, which is why we're sharing a confirmed set of vulnerabilities we’ve identified after using advanced AI Frontier models to proactively scan our code as part of our continuous security hardening work. 

 

Applies To

  • Okta Access Gateway (OAG)
  • Okta Hyperdrive Agent
  • Okta Privileged Access (OPA)
  • Okta Verify for Windows

Solution

Administrators must perform appropriate version upgrades to maintain a secure environment

Our priority is to help customers quickly find the information that is relevant to them and understand any actions they may need to take. Our monitoring telemetry shows no evidence of exploitation, with discovered vulnerabilities ranging from Medium to High severity (CVSS 4.8–8.1).

 

Review the security advisories and apply the necessary updates. Each advisory includes specific, actionable guidance so you can take the steps that matter for your organization.

  1. Review Okta Security Advisories: Public-facing advisories are the primary source of issue-specific information and guidance.

  2. Stay up to date: Check the Okta Security Advisories page regularly for the latest published guidance.

Security Advisories categorized by product

Review the listed categories to find the specific security advisories and corresponding product update links for each product.

Okta Access Gateway (OAG)

 

Okta Hyperdrive Agent

 

Okta Privileged Access (OPA)

 

Okta Verify for Windows

 

Why are we sharing this security guidance?

This security guidance reflects our ongoing focus on continuous hardening and proactive vulnerability identification. By providing timely, accessible guidance, we help our customers understand what's relevant to their environments and take action when needed. 

 

We're committed to raising the bar for the identity industry and delivering on the Okta Secure Identity Commitment (OSIC). Security is foundational to identity, and we invest in keeping our products hardened and secure while advancing transparency and stronger security practices across the ecosystem.

 

How can you confirm what products you are using?

Launch the Okta Admin Console for your Org, and verify individual products and versions by using the information below.

  • For Okta Access Gateway (OAG), navigate to Settings > Downloads. Its presence in the list of downloads confirms its applicability.
  • For Okta Hyperdrive Agent, navigate to Applications and Resources > Applications, then search for “Epic Hyperdrive EPCS”, or a similar “Epic EPCS” application, and verify that there’s an active integration.
  • For Okta Privileged Access (OPA), navigate to Applications and Resources > Applications > Browse App Catalog, then search for “Okta Privileged Access” and verify that it’s an active integration.
  • For Okta Verify for Windows, navigate to Directory > Devices, then Filter Platform to Windows. Click the name of the target Windows device to launch the device detail view, then verify the current in-use version of Okta Verify.

 

Additional resources

Recommended content

Loading
Security Advisory Summary: September 2026 | Okta Support