Skip to Content

May 2026

29 May 2026 by
Tiberiu-Septimiu Ungurianu
Brought to you by Third Wave Identity

πŸ” SailPoint Identity Security Cloud – May 2026 Highlights

Claude Enterprise Connector Launch

22 May 2026 β€” SailPoint introduced a Claude Enterprise connector, enabling aggregation of users, groups, roles, and managed agents to support governance of AI-driven enterprise environments.

Quick Compliance Connector Expansion

15–22 May 2026 β€” SailPoint expanded Quick Compliance support across multiple SaaS platforms, making it easier to configure read-only account and entitlement aggregation.

Data Access Security Auto-Revocation

15 May 2026 β€” Administrators and Compliance Managers can now configure automatic revocation campaigns for SharePoint Online and OneDrive records.

Workflows Search & Execution Visibility

8 May 2026 β€” Workflow history and lifecycle events are now available in Search, with new Manager and Executions views improving operational visibility.

Harbour Pilot Access Requests for Others

1 May 2026 β€” Harbour Pilot now supports natural language access requests on behalf of another user, helping streamline onboarding and role-change workflows.

πŸ” Idira (CyberArk) – May 2026 Security Highlights

Critical Weak Authentication Risk in z/OS Credential Provider CCP Deployments

27 May 2026 β€” CyberArk disclosed a critical issue where incomplete IIS configuration guidance for Central Credential Provider deployments in z/OS environments could lead to weak authentication scenarios.

HTML5 Gateway Denial-of-Service Vulnerability

20 May 2026 β€” A high-severity vulnerability affecting HTML5 Gateway deployments could allow denial-of-service attacks against PAM session infrastructure.

Multi-Product Secrets Manager & Credential Provider Security Bulletin

13 May 2026 β€” CyberArk reported issues across Secrets Manager, CCP, z/OS Credential Provider, and Credential Provider installations, including token forgery risks, identity verification bypass, DoS conditions, and sensitive information exposure.

PSM, PSMP & Vault Session Isolation Security Fixes

13 May 2026 β€” CyberArk addressed vulnerabilities affecting PSM, PSMP, Vault/Infra, and Vendor PAM connectors, including session isolation bypasses, credential exposure risks, command injection paths, and Vault denial-of-service scenarios.

Endpoint Privilege Manager Agent Privilege Escalation Risk

13 May 2026 β€” CyberArk released fixes for a high-severity Endpoint Privilege Manager vulnerability affecting Windows, macOS, and Linux agents prior to version 26.5.

πŸ” Delinea - StrongDM – May 2026 Highlights

Enhanced Diagnostic Reporting for HTTP Proxy Configuration

16 May 2026 β€” StrongDM expanded diagnostic visibility by adding operating system HTTP proxy configuration details to the sdm doctor report.

TLS xRDP Connection Support Added

13 May 2026 β€” Added support for TLS-secured xRDP connections, extending secure remote desktop capabilities for Linux-based environments and OCI virtual machines.

RDP Replay Timezone Handling Fix

6 May 2026 β€” Fixed an issue where sdm rdp replay --download failed with a β€œsession not found” error on systems using positive UTC offsets.

Point-in-Time Requestable Entitlement Queries

4 May 2026 β€” Introduced sdm audit requestable-entitlements, enabling point-in-time entitlement visibility across users, roles, and resources.

Kubernetes Driver Memory Leak Fix

1 May 2026 β€” Resolved a memory leak affecting long-running Kubernetes driver operations, including shell sessions, command execution, file transfers, and port forwarding.


Tiberiu-Septimiu Ungurianu 29 May 2026
Share this post
Archive