Skip to content

CVE-2026-11928 CVE-2026-11921 CVE-2026-12101 CVE-2026-11926 CVE-2026-11929 CVE-2026-12358 CVE-2026-13260 CVE-2026-11934 CVE-2026-13297 CVE-2026-11927

IBM Verify Identity Access and Security Verify Access buffer overflow among multiple addressed issues (CVE-2026-11928)

Critical 9.8 Vendor: IBM Published

IBM has addressed multiple vulnerabilities in Verify Identity Access and Security Verify Access, including a network-reachable buffer overflow scored CVSS 9.8. Apply IBM's update and review exposed instances.

What happened

IBM's advisory bundles several vulnerabilities in Verify Identity Access and Security Verify Access. The most severe, CVE-2026-11928, is a buffer overflow with CVSS 9.8. It is reachable over the network, requires no privileges and no user interaction, and has high impact on confidentiality, integrity and availability. A separate critical issue, CVE-2026-11921, concerns container deployments where management password changes may not be applied correctly; it has CVSS 9.1 and high confidentiality and integrity impact.

Other issues include improper validation of user-supplied requests or input that could let administrators execute commands beyond their entitlements (CVE-2026-12101 at CVSS 8.1 and CVE-2026-11934 at CVSS 7.2), three denial-of-service vulnerabilities from insufficient validation of incoming request resources (CVE-2026-11926, CVE-2026-12358 and CVE-2026-13260, each CVSS 7.5), and reverse proxy issues that may weaken cryptographic validation or allow parameter injection in requests to third-party services (CVE-2026-11929 and CVE-2026-11927). Advanced Access Control may also permit information disclosure (CVE-2026-13297, CVSS 7.5).

The available data does not report active exploitation, and the issues are not listed in CISA KEV. IBM's bulletin states fixes are available.

Who is affected

IBM lists the following affected products and ranges:

  • Verify Identity Access 11.0.0 through 11.0.3 Interim Fix 001
  • Verify Identity Access Container 11.0.0 through 11.0.3 Interim Fix 001
  • Security Verify Access 10.0.0 through 10.0.9.2 Interim Fix 001
  • Security Verify Access Container 10.0.0 through 10.0.9.2 Interim Fix 001

Both traditional and container deployments are in scope. If you run either product as an identity and access management gateway, or in the reverse proxy role, confirm which line and build you have.

What to do now

  1. Apply the fixes IBM has published. The bulletin is at https://www.ibm.com/support/pages/node/7286188. The CVE data does not name the fixed builds, so confirm the exact target build for your product line with IBM.
  2. Inventory every Verify Identity Access and Security Verify Access instance, including container deployments, using the affected ranges above.
  3. Treat internet-facing instances as the priority. The highest-scoring issues are reachable over the network with no credentials and no user interaction.
  4. Restrict access to management interfaces and, where the product is used as a reverse proxy, review your third-party service request handling and cryptographic validation settings against IBM's guidance.
  5. Enable and monitor logs for unexpected privileged command execution, management password changes and unexplained service restarts.

How to detect it

IBM's bulletin does not provide specific indicators of compromise. Start by locating any Verify Identity Access or Security Verify Access instance reachable from untrusted networks, because the critical issues are network-reachable without authentication. Focus log review on unexpected privileged operations, management password changes and repeated service restarts.

Beyond the patch

Identity access infrastructure is often internet-facing and holds significant trust; after patching, confirm that exposure and vendor risk are under control. Virtual CISO Services (vCISO) helps identify and reduce exposed services, and Supply Chain Defense & Third-Party Risk helps track vendor software such as IBM's within your estate.

Affected and fixed versions

ProductAffectedFixed in
CVE-2026-11928
Verify Identity Access
11.0.0 – ≤ 11.0.3 Interim Fix 001No fixed version listed yet
CVE-2026-11928
Security Verify Access
10.0.0 – ≤ 10.0.9.2 Interim Fix 001No fixed version listed yet
CVE-2026-11928
Verify Identity Access Container
11.0.0 – ≤ 11.0.3 Interim Fix 001No fixed version listed yet
CVE-2026-11928
Security Verify Access Container
10.0.0 – ≤ 10.0.9.2 Interim Fix 001No fixed version listed yet
CVE-2026-11921
Verify Identity Access
11.0.0 – ≤ 11.0.3 Interim Fix 001No fixed version listed yet
CVE-2026-11921
Security Verify Access
10.0.0 – ≤ 10.0.9.2 Interim Fix 001No fixed version listed yet
CVE-2026-11921
Verify Identity Access Container
11.0.0 – ≤ 11.0.3 Interim Fix 001No fixed version listed yet
CVE-2026-11921
Security Verify Access Container
10.0.0 – ≤ 10.0.9.2 Interim Fix 001No fixed version listed yet
CVE-2026-12101
Verify Identity Access
11.0.0 – ≤ 11.0.3 Interim Fix 001No fixed version listed yet
CVE-2026-12101
Security Verify Access
10.0.0 – ≤ 10.0.9.2 Interim Fix 001No fixed version listed yet
CVE-2026-12101
Verify Identity Access Container
11.0.0 – ≤ 11.0.3 Interim Fix 001No fixed version listed yet
CVE-2026-12101
Security Verify Access Container
10.0.0 – ≤ 10.0.9.2 Interim Fix 001No fixed version listed yet
CVE-2026-11926
Verify Identity Access
11.0.0 – ≤ 11.0.3 Interim Fix 001No fixed version listed yet
CVE-2026-11926
Security Verify Access
10.0.0 – ≤ 10.0.9.2 Interim Fix 001No fixed version listed yet
CVE-2026-11926
Verify Identity Access Container
11.0.0 – ≤ 11.0.3 Interim Fix 001No fixed version listed yet
CVE-2026-11926
Security Verify Access Container
10.0.0 – ≤ 10.0.9.2 Interim Fix 001No fixed version listed yet
CVE-2026-11929
Verify Identity Access
11.0.0 – ≤ 11.0.3 Interim Fix 001No fixed version listed yet
CVE-2026-11929
Security Verify Access
10.0.0 – ≤ 10.0.9.2 Interim Fix 001No fixed version listed yet
CVE-2026-11929
Verify Identity Access Container
11.0.0 – ≤ 11.0.3 Interim Fix 001No fixed version listed yet
CVE-2026-11929
Security Verify Access Container
10.0.0 – ≤ 10.0.9.2 Interim Fix 001No fixed version listed yet
CVE-2026-12358
Verify Identity Access
11.0.0 – ≤ 11.0.3 Interim Fix 001No fixed version listed yet
CVE-2026-12358
Security Verify Access
10.0.0 – ≤ 10.0.9.2 Interim Fix 001No fixed version listed yet
CVE-2026-12358
Verify Identity Access Container
11.0.0 – ≤ 11.0.3 Interim Fix 001No fixed version listed yet
CVE-2026-12358
Security Verify Access Container
10.0.0 – ≤ 10.0.9.2 Interim Fix 001No fixed version listed yet
CVE-2026-13260
Verify Identity Access
11.0.0 – ≤ 11.0.3 Interim Fix 001No fixed version listed yet
CVE-2026-13260
Security Verify Access
10.0.0 – ≤ 10.0.9.2 Interim Fix 001No fixed version listed yet
CVE-2026-13260
Verify Identity Access Container
11.0.0 – ≤ 11.0.3 Interim Fix 001No fixed version listed yet
CVE-2026-13260
Security Verify Access Container
10.0.0 – ≤ 10.0.9.2 Interim Fix 001No fixed version listed yet
CVE-2026-11934
Verify Identity Access
11.0.0 – ≤ 11.0.3 Interim Fix 001No fixed version listed yet
CVE-2026-11934
Security Verify Access
10.0.0 – ≤ 10.0.9.2 Interim Fix 001No fixed version listed yet
CVE-2026-11934
Verify Identity Access Container
11.0.0 – ≤ 11.0.3 Interim Fix 001No fixed version listed yet
CVE-2026-11934
Security Verify Access Container
10.0.0 – ≤ 10.0.9.2 Interim Fix 001No fixed version listed yet
CVE-2026-13297
Verify Identity Access
11.0.0 – ≤ 11.0.3 Interim Fix 001No fixed version listed yet
CVE-2026-13297
Security Verify Access
10.0.0 – ≤ 10.0.9.2 Interim Fix 001No fixed version listed yet
CVE-2026-13297
Verify Identity Access Container
11.0.0 – ≤ 11.0.3 Interim Fix 001No fixed version listed yet
CVE-2026-13297
Security Verify Access Container
10.0.0 – ≤ 10.0.9.2 Interim Fix 001No fixed version listed yet
CVE-2026-11927
Verify Identity Access
11.0.0 – ≤ 11.0.3 Interim Fix 001No fixed version listed yet
CVE-2026-11927
Security Verify Access
10.0.0 – ≤ 10.0.9.2 Interim Fix 001No fixed version listed yet
CVE-2026-11927
Verify Identity Access Container
11.0.0 – ≤ 11.0.3 Interim Fix 001No fixed version listed yet
CVE-2026-11927
Security Verify Access Container
10.0.0 – ≤ 10.0.9.2 Interim Fix 001No fixed version listed yet

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.