IBM Security Verify Access and Verify Identity Access: two unauthenticated remote code execution flaws (CVE-2026-78401, CVE-2026-78406, CVSS 9.8) among 22 CVEs fixed; update to 10.0.9.3 or 11.0.3.1
IBM published a security bulletin on 7 October 2026 for IBM Security Verify Access 10.0 to 10.0.9.2 and IBM Verify Identity Access 11.0 to 11.0.3, the access-management and reverse-proxy gateway (formerly ISAM/WebSEAL) many organisations put in front of web applications for single sign-on and multi-factor login. The worst issues, CVE-2026-78401 and CVE-2026-78406 (both CVSS 9.8), let a remote attacker with no login run arbitrary code through deserialisation of untrusted data (CWE-502). The bulletin lists 22 CVEs in all. It also covers CVE-2026-16916 (9.1, authenticated code execution through a protection mechanism failure in the appliance), CVE-2026-17189 (8.2, reflected cross-site scripting), CVE-2026-19878 (6.5, bypass of extra authentication workflow steps) and denial-of-service, log-forgery and local management interface flaws. Appliance and container editions are both affected. IBM lists no workarounds and no exploitation. Primary: IBM.
- Product
- IBM Security Verify Access and IBM Verify Identity Access (appliance and container)
- Versions
- Security Verify Access 10.0 to 10.0.9.2; Verify Identity Access 11.0 to 11.0.3
- CVSS
- (CVE-2026-78401, CVE-2026-78406); 9.1 (CVE-2026-16916); 8.2 (CVE-2026-17189)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- Update appliances to IBM Security Verify Access 10.0.9.3 or IBM Verify Identity Access 11.0.3.1, and pull the matching container images. There is no workaround, so treat internet-facing reverse proxies as first priority and keep the local management interface off untrusted networks.
Primary: IBM — Security Bulletin: vulnerabilities addressed in IBM Verify Identity Access and IBM Security Verify Access (7 Oct 2026) · CVE: CVE-2026-78401, CVE-2026-78406, CVE-2026-16916, CVE-2026-17189, CVE-2026-19878 · NVD — CVE-2026-78401 (CNA IBM, published 8 Oct 2026)
