Identity & Access Management · head-to-head
IBM Security Identity vs Microsoft Identity
On-prem IAM/IGA/PAM/MFA: directories, federation, privileged access, SSO. Counts are scoped to this segment and the selected published-date window. IBM Security Identity carries 20.5× the disclosed CVE volume of Microsoft Identity. Volume reflects disclosure practice and install base as much as code quality — read it with the severity mix. Sourced from the NIST NVD; lower counts indicate a smaller disclosed vulnerability surface — not necessarily lower risk.
Disclosure record
Bars are normalized per row to the larger value; the leading count is emphasized.
| IBM Security Identity | Metric | Microsoft Identity | ||
|---|---|---|---|---|
| 41 | Total CVEs | 2 | ||
| 5 | Critical | 0 | ||
| 16 | High | 1 | ||
| 16 | Medium | 1 | ||
| 4 | Low | 0 | ||
| 107 | Open in latest | 6 |
Risk profile
Each severity band as a share of the vendor's own total — strips out raw volume so the profiles compare directly.
IBM Security Identity
12.2% critical- Critical
- 512.2%
- High
- 1639.0%
- Medium
- 1639.0%
- Low
- 49.8%
Microsoft Identity
0.0% critical- Critical
- 00.0%
- High
- 150.0%
- Medium
- 150.0%
- Low
- 00.0%
Recent activity
Latest in-window disclosures per vendor, newest first. Each ID links to its NVD record.
IBM Security Identity
| CVE | Severity | CVSS | Published |
|---|---|---|---|
| CVE-2026-17616(opens NVD record) | Medium | 6.8 | Aug 12, 2026 |
| CVE-2026-11932(opens NVD record) | Medium | 5.3 | Aug 12, 2026 |
| CVE-2026-13267(opens NVD record) | High | 8.1 | Aug 12, 2026 |
| CVE-2026-12618(opens NVD record) | High | 7.2 | Aug 12, 2026 |
| CVE-2026-12359(opens NVD record) | High | 8.1 | Aug 12, 2026 |
| CVE-2026-12005(opens NVD record) | High | 7.2 | Aug 12, 2026 |
Microsoft Identity
| CVE | Severity | CVSS | Published |
|---|---|---|---|
| CVE-2026-65673(opens NVD record) | High | 7.8 | Aug 11, 2026 |
| CVE-2025-26685(opens NVD record) | Medium | 6.5 | May 13, 2025 |
Track new CVEs for these vendors
Get an email the moment a new vulnerability is disclosed for the products you rely on.