Okta
Security Risk Profile
47
/100
mediumSecurity Risk Score
Comprehensive risk assessment based on 21 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from April 2, 2021 to present
21
Total CVEs
11
Critical+High
1
Exploited
5
Unpatched
Threat Assessment
Avg CVSS
7.2
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
5
Critical/High
Risk Level
47/100
medium
⚠️ 1 Active Exploits
Severity Distribution
Critical
1High
10Medium
5Low
1Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
4Age Distribution
Common Weaknesses (CWE)
1
Command Injection
4
2
Path Traversal
2
3
XSS
2
4
OS Command Injection
2
5
Race Condition
1
Most Affected Products
1. Okta Active Directory Agent4
2. maven/com.okta.sdk:okta-sdk-root2
3. Okta Java Management SDK2
4. Okta Okta2
5. Okta Verify Windows2
Recent Vulnerabilities
See more →CVE-2025-67505
CVSS 8.4high
Race condition in the Okta Java SDK
12/10/2025
CVE-2025-66033
CVSS 5.3medium
Improper Memory Cleanup in the Okta Java SDK
12/10/2025
https://www.bleepingcomputer.com/news/security/how-attackers-are-still-phishing-phishing-resistant-authentication/
unknown
How attackers are still phishing "phishing-resistant" authentication
7/29/2025🔧 No Patch
CVE-2025-7371
CVSS 6.8EPSS 0%medium
7/22/2025🔧 No Patch
https://www.zdnet.com/article/phishers-built-fake-okta-and-microsoft-365-login-sites-with-ai-heres-how-to-protect-yourself/
unknown
Phishers built fake Okta and Microsoft 365 login sites with AI - here's how to protect yourself
7/2/2025🔧 No Patch
https://www.darkreading.com/vulnerabilities-threats/will-2025-see-rise-nhi-attacks
unknown
Will 2025 See a Rise of NHI Attacks?
1/22/2025⚠ Exploited🔧 No Patch
CVE-2024-9875
CVSS 7.1EPSS 0%high
11/20/2024
CVE-2024-9191
CVSS 7.8EPSS 0%high
11/1/2024
CVE-2024-10327
CVSS 8.1high
10/24/2024
CVE-2024-7061
CVSS 7.8EPSS 0%high
8/7/2024
Monitor Okta in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.