Cyber & AI intelligence
Wasteland.
Briefs indexed3091
Issues31
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-78401 2026-10-08

Critical Deserialization Flaw in IBM Security Verify Access and Verify Identity Access Enables Unauthenticated RCE (CVE-2026-78401)

"CVE-2026-78401 is a critical (CVSS 9.8) flaw in IBM Security Verify Access and IBM Verify Identity Access: the products deserialize untrusted data, which could let a remote attacker execute arbitrary code without…"

CVE-2026-78401 is a critical (CVSS 9.8) flaw in IBM Security Verify Access and IBM Verify Identity Access: the products deserialize untrusted data, which could let a remote attacker execute arbitrary code without authenticating.

What Is It

CVE-2026-78401 is a deserialization-of-untrusted-data weakness (CWE-502) affecting IBM's access management products. According to the NVD description, IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 "could allow a remote unauthenticated attacker to execute arbitrary code on the system."

IBM PSIRT ([email protected]) reported the vulnerability. NVD published it on 2026-10-08, and its status is currently "Awaiting Analysis."

Why It Matters

IBM's CVSS v3.1 base score is 9.8 (Critical), with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. In plain terms:

These products handle identity and access, so arbitrary code execution on them is serious exposure.

As of this writing, CISA's Known Exploited Vulnerabilities (KEV) catalog has no entry for CVE-2026-78401. That means KEV does not confirm active exploitation at this time.

What's Vulnerable

According to the NVD affected-product data:

Product Affected Versions
IBM Security Verify Access 10.0 through 10.0.9.2
IBM Security Verify Access Container 10.0 through 10.0.9.2
IBM Verify Identity Access 11.0 through 11.0.3
IBM Verify Identity Access Container 11.0 through 11.0.3

Both the appliance/software and container versions of each product line are listed as affected.

Patch Status

The supplied data does not name fixed versions or specific remediation steps. IBM has published a security bulletin for this vulnerability, linked below. Organizations running affected versions should check that bulletin for fixes or workarounds and treat remediation as a priority, given the critical severity and the fact that no authentication is needed. CISA has not issued a KEV required action, since there is no KEV listing.

Sources