Vulnerability
Published 2026-10-07
Verified 2026-10-09

IBM Security Verify Access and Verify Identity Access: two unauthenticated remote code execution flaws (CVE-2026-78401, CVE-2026-78406, CVSS 9.8) among 22 CVEs fixed; update to 10.0.9.3 or 11.0.3.1

IBM published a security bulletin on 7 October 2026 for IBM Security Verify Access 10.0 to 10.0.9.2 and IBM Verify Identity Access 11.0 to 11.0.3, the access-management and reverse-proxy gateway (formerly ISAM/WebSEAL) many organisations put in front of web applications for single sign-on and multi-factor login. The worst issues, CVE-2026-78401 and CVE-2026-78406 (both CVSS 9.8), let a remote attacker with no login run arbitrary code through deserialisation of untrusted data (CWE-502). The bulletin lists 22 CVEs in all. It also covers CVE-2026-16916 (9.1, authenticated code execution through a protection mechanism failure in the appliance), CVE-2026-17189 (8.2, reflected cross-site scripting), CVE-2026-19878 (6.5, bypass of extra authentication workflow steps) and denial-of-service, log-forgery and local management interface flaws. Appliance and container editions are both affected. IBM lists no workarounds and no exploitation. Primary: IBM.

Product
IBM Security Verify Access and IBM Verify Identity Access (appliance and container)
Versions
Security Verify Access 10.0 to 10.0.9.2; Verify Identity Access 11.0 to 11.0.3
CVSS
(CVE-2026-78401, CVE-2026-78406); 9.1 (CVE-2026-16916); 8.2 (CVE-2026-17189)
Exploited in Australia?
unknown
Patch to
Update appliances to IBM Security Verify Access 10.0.9.3 or IBM Verify Identity Access 11.0.3.1, and pull the matching container images. There is no workaround, so treat internet-facing reverse proxies as first priority and keep the local management interface off untrusted networks.

Primary: IBM — Security Bulletin: vulnerabilities addressed in IBM Verify Identity Access and IBM Security Verify Access (7 Oct 2026) · CVE: CVE-2026-78401, CVE-2026-78406, CVE-2026-16916, CVE-2026-17189, CVE-2026-19878 · NVD — CVE-2026-78401 (CNA IBM, published 8 Oct 2026)

vulnerabilities identity network