Vulnerability
Published 2026-08-04
Verified 2026-09-19

CyberArk / Idira: CA26-37 Privilege Cloud CPM and CA26-38 Secrets Manager

CyberArk (now Idira, the Palo Alto Networks identity security platform) published security bulletins CA26-37 and CA26-38. The public Technical Community notice, edited 4 August 2026, says CA26-37 is High severity and affects Privilege Cloud Central Policy Manager (CPM), all versions prior to 15.0, and CA26-38 is High severity and affects Secrets Manager, Self Hosted, version 13.9.0. Full technical detail sits behind the CyberArk/Idira Technical Community login. No CVE identifiers or CVSS vectors are in that public post. Idira is the May 2026 rebrand of CyberArk after the Palo Alto Networks acquisition; it is not a separate invented product. Confirm the exact patched builds from the logged-in bulletins before upgrading.

Product
CyberArk/Idira Privilege Cloud CPM; Secrets Manager Self Hosted
Versions
CPM all versions prior to 15.0; Secrets Manager Self Hosted 13.9.0
Exploited in Australia?
unknown
Patch to
CPM 15.0 or later (community confirmed 15.0.0.2 includes related CPM plugin patches); Secrets Manager per CA26-38

Primary: CyberArk/Idira security bulletin topic · Vendor: CyberArk is now Idira (FAQ) · Community notice CA26-37 / CA26-38

vulnerabilities identity cloud