Severity: HighAction: Review

VU#273940: Enterprise Access Management EAM does not rotate RSA keys

Overview Imprivata Enterprise Access Management (EAM), an authentication and single sign-on platform for enterprise and clinical environments, contains a vulnerability in versions 26.2.6 and below. The product provides no supported mechanism to rotate its RSA key pair after deployment, meaning the same key pair is used indefinitely to generate the appliance's X.509…

Excerpt from the primary source: CERT/CC Vulnerability Notes

Who is affected

Enterprises

What you should do · Review

Review whether your organization uses the affected products and assess exposure using the linked advisories.

Automated guidance based on this story's classification. Check the linked advisories for specifics.

Sources

We link to original and authoritative sources. Headlines and excerpts belong to their publishers.

Government advisory

VU#273940: Enterprise Access Management EAM does not rotate RSA keys CERT/CC Vulnerability Notes · kb.cert.org · Sep 23, 2026 · Primary source
Severity: Informational

tenfold CE: Our free Identity Governance tool just got 2 new features

tenfold has added shared content governance and real-time event auditing to its free Community Edition for organizations with under 150 users. The new features help teams manage Microsoft 365 sharing and investigate suspicious identity activity.

Severity: HighAction: Be aware

​​Beyond source code: A path to the keys to the kingdom

Explore how Storm-3068 turned a compromised identity into broader cloud access and the steps organizations can take to defend their identities, pipelines, and cloud infrastructure.

Severity: HighAction: Be aware

Storm-3168: Agentic-driven cloud attacks using compromised service principals

Microsoft details JADEPUFFER-linked Azure reconnaissance, resource deletion, and credential access using compromised service principals, identifying the activity as associated with Storm-3168 and providing guidance for defenders.