Frequency
2
occurrences
First Seen
September 16, 2026
Last Seen
September 16, 2026
Exploited in Wild
—
Ransomware Use
—
Public Exploits
—
Attack Vector
—
Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
On September 15, 2026, Delinea disclosed two unauthenticated critical vulnerabilities in Secret Server: CVE-2026-15638 (padding oracle, CVSS 9.1) and CVE-2026-15640 (SAML bypass, CVSS 9.5). These vulnerabilities affect versions 10.5.0 to 12.1.3 and can be exploited by unauthenticated attackers to ma...
Public Exploits
Checking GitHub for proof-of-concept code…