Weekly roundup
IBM Security Verify Access week 41 2026: five critical flaws lead 22 CVEs
IBM published 22 CVEs for IBM Security Verify Access in week 41 of 2026. Five are critical, including unauthenticated remote code execution and authentication bypass; none are listed in CISA KEV or as exploited. Fixed versions: 10.0.9.3 and 11.0.3.1.
The release at a glance
IBM's release for week 41 of 2026 (5 October – 11 October 2026) covers 22 CVEs in the IBM Security Verify Access family, including Verify Identity Access and the container editions. The CVEs were published on 8 October 2026, and IBM's advisory is the reference for this release. The severity split is five critical, five high, ten medium and two low. The critical set is dominated by network-reachable issues: CVE-2026-78406 and CVE-2026-78401 are 9.8 deserialisation flaws that can lead to unauthenticated remote code execution, CVE-2026-19491 and CVE-2026-16823 allow authentication bypass, and CVE-2026-16916 offers authenticated code execution with critical severity. IBM lists fixed versions 10.0.9.3 for Security Verify Access and 11.0.3.1 for Verify Identity Access. None of the 22 CVEs is in CISA KEV or marked as exploited.
What matters most
Review the five unauthenticated or authentication-bypass criticals first. CVE-2026-78406 and CVE-2026-78401 are both 9.8 critical deserialisation vulnerabilities. Their CVSS vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, meaning a remote attacker can gain full confidentiality, integrity and availability impact without privileges or user interaction. CVE-2026-19491 and CVE-2026-16823 are 9.1 authentication bypass flaws with the same unauthenticated network reachability, but their impact is limited to confidentiality and integrity. CVE-2026-16916 is a 9.1 protection mechanism failure that requires a high-privilege account and has changed scope across the system. These affect IBM Security Verify Access 10.0 through 10.0.9.2, IBM Verify Identity Access 11.0 through 11.0.3, and the corresponding Security Verify Access Container and Verify Identity Access Container editions.
Next, review CVE-2026-19482 and CVE-2026-18740, both 8.8 high-severity command or argument injection flaws requiring low-privileged authenticated access. CVE-2026-17189 is an 8.2 cross-site scripting issue that can embed JavaScript in the Web UI and potentially lead to credential disclosure within a trusted session. The ten highest-scoring CVEs in this release have separate advisory pages on this site.
Patch in this order
- Locate and inventory every affected deployment: IBM Security Verify Access 10.0 through 10.0.9.2, IBM Verify Identity Access 11.0 through 11.0.3, and both container editions. Pay particular attention to internet-facing instances and any management Web UI.
- Patch CVE-2026-78406 and CVE-2026-78401 first; they are unauthenticated network-reachable remote code execution flaws. Then patch CVE-2026-19491 and CVE-2026-16823, the authentication bypass issues. IBM lists fixed versions 10.0.9.3 for Security Verify Access and 11.0.3.1 for Verify Identity Access.
- Patch CVE-2026-16916, CVE-2026-19482 and CVE-2026-18740 next. These require a valid account but can still lead to code or command execution. CVE-2026-19494, an 8.1 authentication-bypass, and CVE-2026-19493, a 7.5 path traversal allowing arbitrary file write, are also on separate advisories and should follow in the same cycle.
- Address CVE-2026-17189 and the remaining medium and low severity CVEs during the standard patch cycle, prioritising any Web UI exposure. There are no CISA KEV entries in this release, so no CISA due date applies.
Beyond the patch
An access management product with several network-reachable, pre-authentication flaws is a good moment to confirm exposure before patching. Virtual CISO Services can help locate Verify Access instances and open ports that should not be reachable, and Implementation & Assessment Services can validate the deserialisation and authentication fixes before enterprise-wide rollout. If any instance was exposed before patching, Managed Detection & Response can help detect code execution or credential misuse after the fact.
Every CVE in this release
| CVE | Product | Severity | |
|---|---|---|---|
| CVE-2026-78406 | Security Verify Access | Critical 9.8 | Advisory → |
| CVE-2026-78401 | Security Verify Access | Critical 9.8 | Advisory → |
| CVE-2026-19491 | Security Verify Access | Critical 9.1 | Advisory → |
| CVE-2026-16916 | Security Verify Access | Critical 9.1 | Advisory → |
| CVE-2026-16823 | Security Verify Access | Critical 9.1 | Advisory → |
| CVE-2026-19482 | Security Verify Access | High 8.8 | Advisory → |
| CVE-2026-18740 | Security Verify Access | High 8.8 | Advisory → |
| CVE-2026-17189 | Security Verify Access | High 8.2 | Advisory → |
| CVE-2026-19494 | Security Verify Access | High 8.1 | Advisory → |
| CVE-2026-19493 | Security Verify Access | High 7.5 | Advisory → |
| CVE-2026-19878 | Security Verify Access | Medium 6.5 | |
| CVE-2026-78399 | Security Verify Access | Medium 6.5 | |
| CVE-2026-11888 | Security Verify Access | Medium 6.4 | |
| CVE-2026-19498 | Security Verify Access | Medium 5.9 | |
| CVE-2026-11930 | Security Verify Access | Medium 5.9 | |
| CVE-2026-12109 | Security Verify Access | Medium 5.5 | |
| CVE-2026-78407 | Security Verify Access | Medium 5.4 | |
| CVE-2026-16830 | Security Verify Access | Medium 5.4 | |
| CVE-2026-11936 | Security Verify Access | Medium 4.9 | |
| CVE-2026-78388 | Security Verify Access | Medium 4.3 | |
| CVE-2026-12091 | Security Verify Access | Low 3.7 | |
| CVE-2026-11939 | Security Verify Access | Low 2.7 |
References
Vendor advisory
CVE
- CVE-2026-78406 — cve.org
- CVE-2026-78406 — NVD
- EUVD-2026-95269 — ENISA EUVD
- CVE-2026-78401 — cve.org
- CVE-2026-78401 — NVD
- EUVD-2026-95270 — ENISA EUVD
- CVE-2026-19491 — cve.org
- CVE-2026-19491 — NVD
- EUVD-2026-95277 — ENISA EUVD
- CVE-2026-16916 — cve.org
- CVE-2026-16916 — NVD
- EUVD-2026-95280 — ENISA EUVD
- CVE-2026-16823 — cve.org
- CVE-2026-16823 — NVD
- EUVD-2026-95282 — ENISA EUVD
- CVE-2026-19482 — cve.org
- CVE-2026-19482 — NVD
- EUVD-2026-95273 — ENISA EUVD
- CVE-2026-18740 — cve.org
- CVE-2026-18740 — NVD
- EUVD-2026-95278 — ENISA EUVD
- CVE-2026-17189 — cve.org
- CVE-2026-17189 — NVD
- EUVD-2026-95279 — ENISA EUVD
- CVE-2026-19494 — cve.org
- CVE-2026-19494 — NVD
- EUVD-2026-95276 — ENISA EUVD
- CVE-2026-19493 — cve.org
- CVE-2026-19493 — NVD
- EUVD-2026-95274 — ENISA EUVD
- CVE-2026-19878 — cve.org
- CVE-2026-19878 — NVD
- EUVD-2026-95268 — ENISA EUVD
- CVE-2026-78399 — cve.org
- CVE-2026-78399 — NVD
- EUVD-2026-95272 — ENISA EUVD