CVE-2026-11928 CVE-2026-11921 CVE-2026-12101 CVE-2026-11926 CVE-2026-11929 CVE-2026-12358 CVE-2026-13260 CVE-2026-11934 CVE-2026-13297 CVE-2026-11927
IBM Verify Identity Access and Security Verify Access buffer overflow among multiple addressed issues (CVE-2026-11928)
IBM has addressed multiple vulnerabilities in Verify Identity Access and Security Verify Access, including a network-reachable buffer overflow scored CVSS 9.8. Apply IBM's update and review exposed instances.
What happened
IBM's advisory bundles several vulnerabilities in Verify Identity Access and Security Verify Access. The most severe, CVE-2026-11928, is a buffer overflow with CVSS 9.8. It is reachable over the network, requires no privileges and no user interaction, and has high impact on confidentiality, integrity and availability. A separate critical issue, CVE-2026-11921, concerns container deployments where management password changes may not be applied correctly; it has CVSS 9.1 and high confidentiality and integrity impact.
Other issues include improper validation of user-supplied requests or input that could let administrators execute commands beyond their entitlements (CVE-2026-12101 at CVSS 8.1 and CVE-2026-11934 at CVSS 7.2), three denial-of-service vulnerabilities from insufficient validation of incoming request resources (CVE-2026-11926, CVE-2026-12358 and CVE-2026-13260, each CVSS 7.5), and reverse proxy issues that may weaken cryptographic validation or allow parameter injection in requests to third-party services (CVE-2026-11929 and CVE-2026-11927). Advanced Access Control may also permit information disclosure (CVE-2026-13297, CVSS 7.5).
The available data does not report active exploitation, and the issues are not listed in CISA KEV. IBM's bulletin states fixes are available.
Who is affected
IBM lists the following affected products and ranges:
- Verify Identity Access 11.0.0 through 11.0.3 Interim Fix 001
- Verify Identity Access Container 11.0.0 through 11.0.3 Interim Fix 001
- Security Verify Access 10.0.0 through 10.0.9.2 Interim Fix 001
- Security Verify Access Container 10.0.0 through 10.0.9.2 Interim Fix 001
Both traditional and container deployments are in scope. If you run either product as an identity and access management gateway, or in the reverse proxy role, confirm which line and build you have.
What to do now
- Apply the fixes IBM has published. The bulletin is at https://www.ibm.com/support/pages/node/7286188. The CVE data does not name the fixed builds, so confirm the exact target build for your product line with IBM.
- Inventory every Verify Identity Access and Security Verify Access instance, including container deployments, using the affected ranges above.
- Treat internet-facing instances as the priority. The highest-scoring issues are reachable over the network with no credentials and no user interaction.
- Restrict access to management interfaces and, where the product is used as a reverse proxy, review your third-party service request handling and cryptographic validation settings against IBM's guidance.
- Enable and monitor logs for unexpected privileged command execution, management password changes and unexplained service restarts.
How to detect it
IBM's bulletin does not provide specific indicators of compromise. Start by locating any Verify Identity Access or Security Verify Access instance reachable from untrusted networks, because the critical issues are network-reachable without authentication. Focus log review on unexpected privileged operations, management password changes and repeated service restarts.
Beyond the patch
Identity access infrastructure is often internet-facing and holds significant trust; after patching, confirm that exposure and vendor risk are under control. Virtual CISO Services (vCISO) helps identify and reduce exposed services, and Supply Chain Defense & Third-Party Risk helps track vendor software such as IBM's within your estate.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| CVE-2026-11928 Verify Identity Access | 11.0.0 – ≤ 11.0.3 Interim Fix 001 | No fixed version listed yet |
| CVE-2026-11928 Security Verify Access | 10.0.0 – ≤ 10.0.9.2 Interim Fix 001 | No fixed version listed yet |
| CVE-2026-11928 Verify Identity Access Container | 11.0.0 – ≤ 11.0.3 Interim Fix 001 | No fixed version listed yet |
| CVE-2026-11928 Security Verify Access Container | 10.0.0 – ≤ 10.0.9.2 Interim Fix 001 | No fixed version listed yet |
| CVE-2026-11921 Verify Identity Access | 11.0.0 – ≤ 11.0.3 Interim Fix 001 | No fixed version listed yet |
| CVE-2026-11921 Security Verify Access | 10.0.0 – ≤ 10.0.9.2 Interim Fix 001 | No fixed version listed yet |
| CVE-2026-11921 Verify Identity Access Container | 11.0.0 – ≤ 11.0.3 Interim Fix 001 | No fixed version listed yet |
| CVE-2026-11921 Security Verify Access Container | 10.0.0 – ≤ 10.0.9.2 Interim Fix 001 | No fixed version listed yet |
| CVE-2026-12101 Verify Identity Access | 11.0.0 – ≤ 11.0.3 Interim Fix 001 | No fixed version listed yet |
| CVE-2026-12101 Security Verify Access | 10.0.0 – ≤ 10.0.9.2 Interim Fix 001 | No fixed version listed yet |
| CVE-2026-12101 Verify Identity Access Container | 11.0.0 – ≤ 11.0.3 Interim Fix 001 | No fixed version listed yet |
| CVE-2026-12101 Security Verify Access Container | 10.0.0 – ≤ 10.0.9.2 Interim Fix 001 | No fixed version listed yet |
| CVE-2026-11926 Verify Identity Access | 11.0.0 – ≤ 11.0.3 Interim Fix 001 | No fixed version listed yet |
| CVE-2026-11926 Security Verify Access | 10.0.0 – ≤ 10.0.9.2 Interim Fix 001 | No fixed version listed yet |
| CVE-2026-11926 Verify Identity Access Container | 11.0.0 – ≤ 11.0.3 Interim Fix 001 | No fixed version listed yet |
| CVE-2026-11926 Security Verify Access Container | 10.0.0 – ≤ 10.0.9.2 Interim Fix 001 | No fixed version listed yet |
| CVE-2026-11929 Verify Identity Access | 11.0.0 – ≤ 11.0.3 Interim Fix 001 | No fixed version listed yet |
| CVE-2026-11929 Security Verify Access | 10.0.0 – ≤ 10.0.9.2 Interim Fix 001 | No fixed version listed yet |
| CVE-2026-11929 Verify Identity Access Container | 11.0.0 – ≤ 11.0.3 Interim Fix 001 | No fixed version listed yet |
| CVE-2026-11929 Security Verify Access Container | 10.0.0 – ≤ 10.0.9.2 Interim Fix 001 | No fixed version listed yet |
| CVE-2026-12358 Verify Identity Access | 11.0.0 – ≤ 11.0.3 Interim Fix 001 | No fixed version listed yet |
| CVE-2026-12358 Security Verify Access | 10.0.0 – ≤ 10.0.9.2 Interim Fix 001 | No fixed version listed yet |
| CVE-2026-12358 Verify Identity Access Container | 11.0.0 – ≤ 11.0.3 Interim Fix 001 | No fixed version listed yet |
| CVE-2026-12358 Security Verify Access Container | 10.0.0 – ≤ 10.0.9.2 Interim Fix 001 | No fixed version listed yet |
| CVE-2026-13260 Verify Identity Access | 11.0.0 – ≤ 11.0.3 Interim Fix 001 | No fixed version listed yet |
| CVE-2026-13260 Security Verify Access | 10.0.0 – ≤ 10.0.9.2 Interim Fix 001 | No fixed version listed yet |
| CVE-2026-13260 Verify Identity Access Container | 11.0.0 – ≤ 11.0.3 Interim Fix 001 | No fixed version listed yet |
| CVE-2026-13260 Security Verify Access Container | 10.0.0 – ≤ 10.0.9.2 Interim Fix 001 | No fixed version listed yet |
| CVE-2026-11934 Verify Identity Access | 11.0.0 – ≤ 11.0.3 Interim Fix 001 | No fixed version listed yet |
| CVE-2026-11934 Security Verify Access | 10.0.0 – ≤ 10.0.9.2 Interim Fix 001 | No fixed version listed yet |
| CVE-2026-11934 Verify Identity Access Container | 11.0.0 – ≤ 11.0.3 Interim Fix 001 | No fixed version listed yet |
| CVE-2026-11934 Security Verify Access Container | 10.0.0 – ≤ 10.0.9.2 Interim Fix 001 | No fixed version listed yet |
| CVE-2026-13297 Verify Identity Access | 11.0.0 – ≤ 11.0.3 Interim Fix 001 | No fixed version listed yet |
| CVE-2026-13297 Security Verify Access | 10.0.0 – ≤ 10.0.9.2 Interim Fix 001 | No fixed version listed yet |
| CVE-2026-13297 Verify Identity Access Container | 11.0.0 – ≤ 11.0.3 Interim Fix 001 | No fixed version listed yet |
| CVE-2026-13297 Security Verify Access Container | 10.0.0 – ≤ 10.0.9.2 Interim Fix 001 | No fixed version listed yet |
| CVE-2026-11927 Verify Identity Access | 11.0.0 – ≤ 11.0.3 Interim Fix 001 | No fixed version listed yet |
| CVE-2026-11927 Security Verify Access | 10.0.0 – ≤ 10.0.9.2 Interim Fix 001 | No fixed version listed yet |
| CVE-2026-11927 Verify Identity Access Container | 11.0.0 – ≤ 11.0.3 Interim Fix 001 | No fixed version listed yet |
| CVE-2026-11927 Security Verify Access Container | 10.0.0 – ≤ 10.0.9.2 Interim Fix 001 | No fixed version listed yet |
References
Vendor advisory
CVE
- CVE-2026-11928 — cve.org
- CVE-2026-11928 — NVD
- CVE-2026-11921 — cve.org
- CVE-2026-11921 — NVD
- CVE-2026-12101 — cve.org
- CVE-2026-12101 — NVD
- CVE-2026-11926 — cve.org
- CVE-2026-11926 — NVD
- CVE-2026-11929 — cve.org
- CVE-2026-11929 — NVD
- CVE-2026-12358 — cve.org
- CVE-2026-12358 — NVD
- CVE-2026-13260 — cve.org
- CVE-2026-13260 — NVD
- CVE-2026-11934 — cve.org
- CVE-2026-11934 — NVD
- CVE-2026-13297 — cve.org
- CVE-2026-13297 — NVD
- CVE-2026-11927 — cve.org
- CVE-2026-11927 — NVD