Critical Vulnerability CVE-2026-12342 Allows Remote Code Execution in SailPoint IdentityIQ
SailPoint has disclosed a critical vulnerability in its IdentityIQ identity management product. The flaw, tracked as CVE-2026-12342, arises from insufficient input validation in the web service API.
According to the advisory released on September 28, 2026, an attacker located on an adjacent network can send specially crafted content that bypasses validation checks. This allows unauthenticated remote code execution directly on the IdentityIQ server.
The CVSSv3.1 base score for the vulnerability is 9.6, placing it in the highest severity category of Critical. The issue requires no authentication and can be exploited over an adjacent network segment.
SailPoint has made patches available for all supported affected versions of IdentityIQ. The company stated that future patch releases will also incorporate the fix.
Related articles
WatchGuard Patches Critical API Flaws in Access Points Allowing Unauthenticated Command Execution
WatchGuard has released firmware version 3.4.8 to address three vulnerabilities affecting its access points, two of which are rated critical. The most severe issues, CVE-2026-86102 and CVE-2026-101891, both scored 9.3 on the CVSS scale and reside in the internal API management service. These flaws permit unauthenticated attackers with network access to execute arbitrary shell commands or bypass access controls without requiring any credentials or valid sessions. A third vulnerability, CVE-2026-87969 with a CVSS score of 8.6, involves command injection through the command-line diagnostic interface but requires authenticated administrator privileges. All firmware versions from 1.0 through 3.4.7 are impacted. The vulnerabilities were disclosed on September 28 with no evidence of active exploitation or public proof-of-concept code available at the time. A compromised access point could serve as an internal foothold for further network attacks due to its visibility into corporate traffic.
Spectre Variant Returns: Branch Target Reuse Attack Extracts Root Password Hash from Linux Memory
Researchers from VUSec and Scuola Superiore Sant’Anna have disclosed Branch Target Reuse, a new Spectre v2 variant that exploits stale branch predictor entries in modern CPUs. The attack targets JIT compilers that generate and reuse executable code at runtime, allowing speculative execution of instructions from previously freed memory regions. On Intel systems with existing mitigations enabled, the researchers demonstrated extraction of the root password hash from the Linux kernel in minutes. Practical proof-of-concept exploits were developed against the Linux kernel, while PoCs were also prepared for Firefox and tested on GraalVM. The issue affects Intel, AMD, and Arm processors, although exploitation success depends on the specific JIT environment and predictor state. Defenses have already been merged into the Linux kernel and GraalVM, while Mozilla continues work on site isolation. The findings highlight that Spectre-class issues remain relevant as long as processors rely on aggressive speculative execution.
EASM Uncovers Forgotten Perimeter Assets Including 11-Year-Old Servers Invisible to Standard Scanners
EASM solutions continuously discover external attack surfaces by starting from public data such as company names, domains, WHOIS records, Certificate Transparency logs, and internet-wide scanners like Shodan and Censys. Unlike traditional vulnerability scanners that only check assets from a predefined list, EASM maps unknown shadow IT including forgotten test servers, abandoned marketing subdomains, exposed APIs, and cloud buckets left open to the internet. The technology follows the same reconnaissance path used by attackers and has become essential for mature vulnerability management programs after years of being considered exotic. Major vendors including Palo Alto Networks Cortex Xpanse, CyCognito, Qualys, Rapid7, and Tenable now lead the market, while Russian providers such as Positive Technologies PT EASM, BI.ZONE EASM, and CyberOK PenOps have grown rapidly since 2022. Without an established process for prioritization and remediation, EASM implementations risk generating overwhelming alert volumes rather than reducing risk. The approach is now viewed as a core component of Continuous Threat Exposure Management (CTEM) frameworks.
Mozilla Releases Firefox 157 with 76 Security Fixes, Shifts to Individual CVE Reporting
Mozilla Foundation has released Firefox 157, addressing 76 vulnerabilities rated at various severity levels. The update also includes patches for the extended support releases Firefox ESR 153.4, ESR 140.17, and ESR 115.42. A key change in this release involves Mozilla's new approach to publishing security advisories, moving from grouping multiple memory safety issues under single CVEs to reporting them individually. Among the high-severity issues fixed are sandbox escape flaws, privilege escalation bugs, use-after-free errors, uninitialized memory problems, and JIT compiler mistakes affecting components such as DOM, Graphics, WebGPU, WebAssembly, and Networking. The ESR versions received 62, 43, and 31 fixes respectively, with 34 rated high in the latest branch. All listed CVEs range from CVE-2026-100756 through CVE-2026-100831.