Cryptorank Critical Vulnerabilities in Delinea Secret Server Expose Sensitive Credentials
Article Content
- •Two critical vulnerabilities disclosed in Delinea Secret Server on September 15, 2026.
- •CVE-2026-15638 allows data manipulation; CVE-2026-15640 enables user impersonation.
- •Organizations must urgently patch to version 12.2.7 or later to mitigate risks.
On September 15, 2026, Delinea disclosed two unauthenticated critical vulnerabilities in Secret Server: CVE-2026-15638 (padding oracle, CVSS 9.1) and CVE-2026-15640 (SAML bypass, CVSS 9.5). These vulnerabilities affect versions 10.5.0 to 12.1.3 and can be exploited by unauthenticated attackers to manipulate sensitive data and impersonate users, including administrators. The vulnerabilities undermine the security of the privileged access management platform, which is crucial for managing SSH keys, API tokens, and other sensitive credentials. Delinea released fixes in version 12.2.000007 on August 28, 2026, and additional remediation in version 12.2.7. These issues are part of a broader cluster of four critical CVEs disclosed within two weeks, highlighting a significant risk for organizations relying on this platform.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track BankUnited and CVE-2026-15638 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…