Friday , July 31 2026

IBM fixed multiple vulns in its products, including critical one

IBM has issued fixes for three security vulnerabilities in its IBM Security Verify Access and IBM Verify Identity Access products. These issues could permit privilege escalation, command execution, and script injection. Customers are urged to install these patches right away to avoid exploitation in production environments.

CVE-2025-36355 lets authenticated users run harmful scripts beyond the product’s control. IBM warns that this could lead to client-side code injection or unauthorized script execution, with a CVSS Base Score of 8.5, indicating high severity.

EDIC Propose to invest $2 billion in an AI data center in Bangladesh

Many groups from different countries want to build AI data centers in Bangladesh. Countries like the UK, Japan, and South...
Read More
EDIC Propose to invest $2 billion in an AI data center in Bangladesh

NVIDIA BlueField Flaw Enables Code Execution Attacks

NVIDIA has revealed a big flaw with its BlueField DPUs and ConnectX networking systems. This issue could let attackers run...
Read More
NVIDIA BlueField Flaw Enables Code Execution Attacks

Massive customer data from India’s Bank of Baroda surfaced online

India's leading state-owned lender Bank of Baroda acknowledged Monday a security incident after reports that approximately 1 terabyte of customer...
Read More
Massive customer data from India’s Bank of Baroda surfaced online

Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

CISA has put the Fortinet FortiOS vulnerability CVE-2025-68686 in its list of known exploited flaws after ongoing attacks. The flaw...
Read More
Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves

OpenAI's CEO Sam Altman says that AI has reached a big milestone. The technology can now make itself better, leading...
Read More
Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves

Shinyhunters claimed and set deadline to publish E&Y data

ShinyHunters has publicly claimed responsibility for the Ernst & Young (EY) data breach. The group posted a message on their...
Read More
Shinyhunters claimed and set deadline to publish E&Y data

Microsoft, NVIDIA and CrowdStrike Initiate Alliance for Open-Source AI Security

Nvidia and over 30 tech firms started a group on Monday to create open-source AI tools for protecting against cyber...
Read More
Microsoft, NVIDIA and CrowdStrike Initiate Alliance for Open-Source AI Security

Google Search Results Reportedly Show Claude AI Shared Chats

Claude's share links from Anthropic showed up in public search results. This raised new privacy worries for users who shared...
Read More
Google Search Results Reportedly Show Claude AI Shared Chats

“PentesterFlow” AI Automation Tool for Penetration Testers and Bug Hunters

PentesterFlow is a new open-source AI tool for command lines. It is made for penetration testers and bug bounty hunters....
Read More
“PentesterFlow” AI Automation Tool for Penetration Testers and Bug Hunters

Jailbreak works against AI Models GPT-5.6, Claude Opus 5, and Fable, Claims Researcher

A famous AI red team expert claimed developing a universal jailbreak that can work against top large language models, like...
Read More
Jailbreak works against AI Models GPT-5.6, Claude Opus 5, and Fable, Claims Researcher

“IBM Security Verify Access could allow a locally authenticated user to execute malicious scripts from outside of its control sphere,” the company explains.

CVE-2025-36356 is a critical vulnerability rated 9.3 on the CVSS scale. It allows local users to gain root privileges due to incorrect permission handling, giving attackers full administrative control from minimal access.

“IBM Security Verify Access could allow a locally authenticated user to escalate their privileges to root due to execution with more privileges than required,” IBM confirms in its bulletin.

CVE-2025-36354 affects systems open to unauthenticated users, allowing execution of arbitrary commands with lower privileges. It arises from improper validation of user input and, while rated 7.3, still poses a risk for externally accessible systems.

“IBM Security Verify Access could allow an unauthenticated user to execute arbitrary commands with lower user privileges on the system due to improper validation of user supplied input,” according to IBM.

“Security vulnerabilities have been addressed in IBM Security Verify Access 10.0.9.0-IF3 and IBM Verify Identity Access 11.0.1.0-IF1,” the advisory states, emphasizing that organizations running earlier versions remain exposed until updates are applied.

IBM has identified the affected products and versions for both containerized and appliance deployments.

IBM Verify Identity Access (Docker & Appliance): Versions 11.0.0.0 – 11.0.1.0
IBM Security Verify Access (Docker & Appliance): Versions 10.0.0.0 – 10.0.9.0-IF2

These vulnerabilities impact systems that control access and verify identities, so it’s essential to patch them quickly for network security.

IBM has released Fix Packs 10.0.9.0-IF3 for Verify Access and 11.0.1.0-IF1 for Verify Identity Access, accessible via IBM Fix Central and container registries.

For container deployments, administrators can pull the latest versions directly from IBM’s registry:

docker pull icr.io/isva/verify-access:[latest-tag] docker pull icr.io/ivia/verify-access:[latest-tag]

Each tag corresponds to the latest patched release and can be verified on IBM’s official documentation portal.

Check Also

SolarWinds

SolarWinds Patches 15 Critical Serv-U Flaws

SolarWinds has shared important security updates for its Serv-U file transfer software. These updates fix …