PT-2026-33646 · Undefined · Undefined
Published
2026-04-19
·
Updated
2026-04-19
·
CVE-2026-51287
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
5/8
Action 4: Apply Critical Patches (24-Hour Priority)
• Okta Identity Cloud CVE-2026-51287: Critical authentication bypass actively exploited April 18–19, 2026; affects workforce and customer identity flows. Patch all tenants per CISA directive issued April 19.
• Elastic Stack (Elasticsearch + Kibana): Two unauthenticated RCE flaws added to CISA KEV catalog on April 19, 2026.
• Microsoft Exchange Online: Apply follow-on patches from yesterday’s (April 18) disclosure; monitor hybrid environments for secondary exploitation.
Immediate steps:
• Deploy patches immediately.
• Enable just-in-time admin access across identity platforms.
• Audit Elastic/Kibana deployments.
Reference: CISA KEV catalog (April 19, 2026) + NIST vulnerability guidelines.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Undefined