IBM released security updates to fix 22 distinct flaws in its identity management software. These IBM Verify Access vulnerabilities include critical bugs that permit remote code execution. Administrators must deploy the latest patches immediately to secure their infrastructure.
- Total: 6 CVEs
- Severity: 5 Critical ยท 1 High
- Actively exploited: None confirmed
- Highest severity: 9.8 (Critical ยท CVSSv3) โ CVE-2026-78401
- Action: Apply the latest security updates now
CISA KEV isn't the only exploit signal. Pro/Team adds a second confirmed-exploit feed.
Try free for 14 daysNotable CVEs
| CVE | CVSS (CVSSv3) | Type | Status |
|---|---|---|---|
| CVE-2026-78401 | 9.8 | CWE-502 | Not exploited |
| CVE-2026-78406 | 9.8 | CWE-502 | Not exploited |
| CVE-2026-16916 | 9.1 | CWE-693 | Not exploited |
| CVE-2026-16823 | 9.1 | CWE-287 | Not exploited |
| CVE-2026-19491 | 9.1 | CWE-287 | Not exploited |
| CVE-2026-17189 | 8.2 | CWE-79 | Not exploited |
Why These Flaws Matter to Enterprise Security
Identity management platforms serve as the digital gates to corporate networks. When these gates fail, unauthorized users gain unrestricted entry to sensitive environments. Therefore, these IBM Verify Access vulnerabilities represent a massive danger to enterprise data. A successful attack could compromise user credentials across the entire organization. Moreover, attackers might disable security protocols entirely to hide their tracks. Network defenders must treat these exposures as highly critical incidents.
How the Attacks Work
The most severe issue involves untrusted data deserialization. According to the security bulletin, “IBM Verify Identity Access could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.” The software processes external data without checking its safety first. Consequently, hackers can inject malicious commands directly into the memory stream. This blind trust in user input creates a direct path for complete system takeover.
Authentication Bypass Mechanisms
Furthermore, several other high-severity flaws enable authentication bypass. Attackers send manipulated HTTP requests to the target appliance. The system fails to validate these requests properly during processing. As a result, remote users can bypass security restrictions and act as administrators. Another bug allows local attackers to run arbitrary code through reflected cross-site scripting. Additionally, attackers can trigger uncontrolled recursion to cause severe denial of service conditions.
Exploitation Status and Affected Installations
Security teams have not confirmed any active exploitation of these flaws in the wild. Also, no public proof-of-concept exploit code exists right now. However, malicious actors analyze security patches very quickly to build working exploits. The exact number of affected installations remains unconfirmed by official sources. Regardless of the installation count, the risk profile demands immediate attention from security personnel.
Vulnerable Software Versions
The security bulletin identifies multiple vulnerable product lines across the IBM ecosystem. Specifically, IBM Security Verify Access versions 10.0 through 10.0.9.2 contain these flaws. In addition, IBM Verify Identity Access versions 11.0 through 11.0.3 require software updates. The container versions of these products share identical version risks. Administrators must check their deployment versions to determine their specific exposure level.
Required Patch and Mitigation Steps
You must upgrade all affected systems to secure them against intrusion. IBM strongly encourages customers to update their systems promptly. Users running version 11 should install IBM Verify Identity Access v11.0.3.1. Similarly, older deployments require an immediate update to IBM Security Verify Access v10.0.9.3. Network administrators should apply these fixes before normal business hours resume to minimize disruption.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!