Skip to content

Weekly roundup

IBM Security Verify Access week 41 2026: five critical flaws lead 22 CVEs

Critical 9.8 Vendor: IBM 22 CVEs in scope Published

IBM published 22 CVEs for IBM Security Verify Access in week 41 of 2026. Five are critical, including unauthenticated remote code execution and authentication bypass; none are listed in CISA KEV or as exploited. Fixed versions: 10.0.9.3 and 11.0.3.1.

The release at a glance

IBM's release for week 41 of 2026 (5 October – 11 October 2026) covers 22 CVEs in the IBM Security Verify Access family, including Verify Identity Access and the container editions. The CVEs were published on 8 October 2026, and IBM's advisory is the reference for this release. The severity split is five critical, five high, ten medium and two low. The critical set is dominated by network-reachable issues: CVE-2026-78406 and CVE-2026-78401 are 9.8 deserialisation flaws that can lead to unauthenticated remote code execution, CVE-2026-19491 and CVE-2026-16823 allow authentication bypass, and CVE-2026-16916 offers authenticated code execution with critical severity. IBM lists fixed versions 10.0.9.3 for Security Verify Access and 11.0.3.1 for Verify Identity Access. None of the 22 CVEs is in CISA KEV or marked as exploited.

What matters most

Review the five unauthenticated or authentication-bypass criticals first. CVE-2026-78406 and CVE-2026-78401 are both 9.8 critical deserialisation vulnerabilities. Their CVSS vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, meaning a remote attacker can gain full confidentiality, integrity and availability impact without privileges or user interaction. CVE-2026-19491 and CVE-2026-16823 are 9.1 authentication bypass flaws with the same unauthenticated network reachability, but their impact is limited to confidentiality and integrity. CVE-2026-16916 is a 9.1 protection mechanism failure that requires a high-privilege account and has changed scope across the system. These affect IBM Security Verify Access 10.0 through 10.0.9.2, IBM Verify Identity Access 11.0 through 11.0.3, and the corresponding Security Verify Access Container and Verify Identity Access Container editions.

Next, review CVE-2026-19482 and CVE-2026-18740, both 8.8 high-severity command or argument injection flaws requiring low-privileged authenticated access. CVE-2026-17189 is an 8.2 cross-site scripting issue that can embed JavaScript in the Web UI and potentially lead to credential disclosure within a trusted session. The ten highest-scoring CVEs in this release have separate advisory pages on this site.

Patch in this order

  1. Locate and inventory every affected deployment: IBM Security Verify Access 10.0 through 10.0.9.2, IBM Verify Identity Access 11.0 through 11.0.3, and both container editions. Pay particular attention to internet-facing instances and any management Web UI.
  2. Patch CVE-2026-78406 and CVE-2026-78401 first; they are unauthenticated network-reachable remote code execution flaws. Then patch CVE-2026-19491 and CVE-2026-16823, the authentication bypass issues. IBM lists fixed versions 10.0.9.3 for Security Verify Access and 11.0.3.1 for Verify Identity Access.
  3. Patch CVE-2026-16916, CVE-2026-19482 and CVE-2026-18740 next. These require a valid account but can still lead to code or command execution. CVE-2026-19494, an 8.1 authentication-bypass, and CVE-2026-19493, a 7.5 path traversal allowing arbitrary file write, are also on separate advisories and should follow in the same cycle.
  4. Address CVE-2026-17189 and the remaining medium and low severity CVEs during the standard patch cycle, prioritising any Web UI exposure. There are no CISA KEV entries in this release, so no CISA due date applies.

Beyond the patch

An access management product with several network-reachable, pre-authentication flaws is a good moment to confirm exposure before patching. Virtual CISO Services can help locate Verify Access instances and open ports that should not be reachable, and Implementation & Assessment Services can validate the deserialisation and authentication fixes before enterprise-wide rollout. If any instance was exposed before patching, Managed Detection & Response can help detect code execution or credential misuse after the fact.

Every CVE in this release

CVEProductSeverity
CVE-2026-78406Security Verify AccessCritical 9.8Advisory →
CVE-2026-78401Security Verify AccessCritical 9.8Advisory →
CVE-2026-19491Security Verify AccessCritical 9.1Advisory →
CVE-2026-16916Security Verify AccessCritical 9.1Advisory →
CVE-2026-16823Security Verify AccessCritical 9.1Advisory →
CVE-2026-19482Security Verify AccessHigh 8.8Advisory →
CVE-2026-18740Security Verify AccessHigh 8.8Advisory →
CVE-2026-17189Security Verify AccessHigh 8.2Advisory →
CVE-2026-19494Security Verify AccessHigh 8.1Advisory →
CVE-2026-19493Security Verify AccessHigh 7.5Advisory →
CVE-2026-19878Security Verify AccessMedium 6.5
CVE-2026-78399Security Verify AccessMedium 6.5
CVE-2026-11888Security Verify AccessMedium 6.4
CVE-2026-19498Security Verify AccessMedium 5.9
CVE-2026-11930Security Verify AccessMedium 5.9
CVE-2026-12109Security Verify AccessMedium 5.5
CVE-2026-78407Security Verify AccessMedium 5.4
CVE-2026-16830Security Verify AccessMedium 5.4
CVE-2026-11936Security Verify AccessMedium 4.9
CVE-2026-78388Security Verify AccessMedium 4.3
CVE-2026-12091Security Verify AccessLow 3.7
CVE-2026-11939Security Verify AccessLow 2.7

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, ENISA EUVD, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.