CVE-2026-80327: Ping Identity Pinggateway
Medium severity, CVSS 5.1. EPSS: 0.4% chance of exploitation in the next 30 days.
An open redirect vulnerability exists in the PingGateway Fragment Filter feature. This issue affects PingGateway versions 7.1.0 and later, 2023.2.0 through 2024.11.1, and 2025.3.0 through 2025.11.1. It is fixed in versions 2024.11.2, 2025.11.2, and 2026.3.0 (and later).
Affected products
- Ping Identity Pinggateway: from 7.1.0, up to and including 7.2.0; from 2023.2.0, up to and including 2024.11.1; from 2025.3.0, up to and including 2025.11.1
Published 2026-10-06. Last modified 2026-10-06.