CVE-2026-51287Patch

MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

4.0/ 10 priority

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-19: 1Active Exploitation · 2026-04-19: 1Patch / Workaround · 2026-04-19: 1Technical Details · 2026-04-19: 104-19
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Adam@seoscottsdale
    Patch

    5/8 Action 4: Apply Critical Patches (24-Hour Priority) • Okta Identity Cloud CVE-2026-51287: Critical authentication bypass actively exploited April 18–19, 2026; affects workforce and customer identity flows. Patch all tenants per CISA directive issued April 19. • Elastic Stack (Elasticsearch + Kibana): Two unauthenticated RCE flaws added to CISA KEV catalog on April 19, 2026. • Microsoft Exchange Online: Apply follow-on patches from yesterday’s (April 18) disclosure; monitor hybrid environments for secondary exploitation. Immediate steps: • Deploy patches immediately. • Enable just-in-time admin access across identity platforms. • Audit Elastic/Kibana deployments. Reference: CISA KEV catalog (April 19, 2026) + NIST vulnerability guidelines.

    Post summary

    The bulletin reports Okta’s CVE‑2026‑51287 authentication bypass was actively exploited mid‑April and urges tenants to patch immediately per a CISA directive, while also noting two Elastic Stack RCE flaws added to the KEV catalog.

    1000077
    12.4K followersView on X

Explore more