TL;DR
IBM patched five IBM Aspera vulnerabilities across two products on July 20, 2026. They affect Aspera Faspex 5 and the Aspera Desktop App. The worst flaws reach a CVSS score of 9.3 and allow code execution.
- Total: 4 CVEs
- Severity: 3 Critical · 1 High
- Actively exploited: None confirmed
- Highest severity: 9.3 (Critical · CVSSv3) — CVE-2026-14973
- Action: Apply the latest security updates now
Notable CVEs
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-14973 | 9.3 | CWE-22 | — | Not exploited |
| CVE-2026-14958 | 9.1 | CWE-78 | — | Not exploited |
| CVE-2026-14959 | 9.1 | CWE-78 | — | Not exploited |
| CVE-2026-14996 | 8.2 | CWE-613 | — | Not exploited |
Why it matters
These IBM Aspera vulnerabilities span two different products. Aspera moves large files for media, research, and enterprise teams. Therefore a server compromise can expose sensitive transfers and stored data.
Two Faspex bugs let an authenticated attacker run arbitrary code. The Desktop App flaws are also serious. One writes files outside the chosen download folder. As a result, an attacker could plant files in sensitive spots.
How the attack works
Faspex 5
CVE-2026-14958 and CVE-2026-14959 both enable command execution. They stem from unquoted shell interpolation and OS command injection. A remote authenticated user triggers them, and each scores 9.1. A separate session flaw, CVE-2026-14996, weakens session expiration.
Desktop App
CVE-2026-14973 is a path traversal issue rated 9.3. It lets files land outside the download destination when a user opens a crafted link. CVE-2026-11980 loads attacker DLLs at start-up for local code execution.
Affected versions
The IBM Aspera vulnerabilities affect a broad version range. Faspex 5 releases 5.0.0 through 5.0.15.4 are affected. The Desktop App is affected from 1.0.5 through 1.0.19. No public exploitation or proof-of-concept has been confirmed.
Patch and mitigation
Update Faspex to 5.0.16, as detailed in IBM’s Faspex advisory. Upgrade the Desktop App to 1.1.0 through the app or IBM Aspera Downloads, per the Desktop App bulletin. IBM lists no workarounds, so patching is the fix. Apply both updates promptly, since they close code execution and file-write risks.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.