Cyber & AI intelligence
Wasteland.
Briefs indexed3091
Issues31
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-78406 2026-10-08

Critical Unauthenticated RCE in IBM Security Verify Access and Verify Identity Access (CVE-2026-78406)

"CVE-2026-78406 is a critical (CVSS 9.8) deserialization flaw in IBM Security Verify Access and IBM Verify Identity Access that could let a remote, unauthenticated attacker execute arbitrary code."

CVE-2026-78406 is a critical (CVSS 9.8) deserialization flaw in IBM Security Verify Access and IBM Verify Identity Access that could let a remote, unauthenticated attacker execute arbitrary code.

What Is It

CVE-2026-78406 is a deserialization-of-untrusted-data weakness (CWE-502) in IBM's access management products. IBM's PSIRT says a remote attacker without authentication could execute arbitrary code on an affected system.

IBM's PSIRT published the record to NVD on 2026-10-08. NVD lists it as "Awaiting Analysis," which means the scoring below comes from IBM as the CNA. NVD has not published its own assessment yet.

Why It Matters

IBM gives the flaw a CVSS v3.1 base score of 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. That vector means:

These products handle access management, so compromising one could expose the authentication layer that sits in front of other applications.

Exploitation status: The supplied CISA KEV data contains no entry for this CVE, so KEV does not confirm active exploitation as of this writing. That can change, and the severity alone makes this a high patching priority.

What's Vulnerable

According to the NVD record, these IBM products are affected:

Product Affected Versions
IBM Security Verify Access 10.0 through 10.0.9.2
IBM Security Verify Access Container 10.0 through 10.0.9.2
IBM Verify Identity Access 11.0 through 11.0.3
IBM Verify Identity Access Container 11.0 through 11.0.3

Both the appliance/software editions and the container editions are listed.

Patch Status

The NVD record links to an IBM support advisory (node 7291628) but does not list fixed versions or specific remediation steps. CISA has published no required action because there is no KEV entry.

Administrators running any affected version should:

  1. Review IBM's advisory for fixed releases and mitigation guidance.
  2. Inventory all Verify Access and Verify Identity Access deployments, including container deployments.
  3. Prioritize patching internet-facing instances, given the unauthenticated network attack vector.

Sources