Wednesday , September 9 2026

IBM fixed multiple vulns in its products, including critical one

IBM has issued fixes for three security vulnerabilities in its IBM Security Verify Access and IBM Verify Identity Access products. These issues could permit privilege escalation, command execution, and script injection. Customers are urged to install these patches right away to avoid exploitation in production environments.

CVE-2025-36355 lets authenticated users run harmful scripts beyond the product’s control. IBM warns that this could lead to client-side code injection or unauthorized script execution, with a CVSS Base Score of 8.5, indicating high severity.

FortiSandbox, FortiOS, FortiProxy ZTNA flaws unveil, while Fortigate firewall actively exploited

An ongoing attack is focused on FortiGate firewalls. Hackers use a serious flaw to install a special Node.js remote access...
Read More
FortiSandbox, FortiOS, FortiProxy ZTNA flaws unveil, while Fortigate firewall actively exploited

Microsoft Patch Tuesday September 2026 Fixed 973 Flaws Fixed, 2 Zero-Days

Microsoft shared its September 2026 security updates on September 8. These updates fix 973 flaws, including two serious issues that...
Read More
Microsoft Patch Tuesday September 2026  Fixed 973 Flaws Fixed, 2 Zero-Days

A single call: ShinyHunters Gained Access to 6 Million Customers’ Records

A single phone call caused one of the biggest data breaches in Dutch history. In early February 2026, the big...
Read More
A single call: ShinyHunters Gained Access to 6 Million Customers’ Records

The first zero-click worm to spread through WeChat calls across iOS and Android

A worm called “WeWorm” can spread through WeChat voice calls on iOS and Android. It takes over a target's WeChat...
Read More
The first zero-click worm to spread through WeChat calls across iOS and Android

USA Bimbo Bakeries Confirms Data Stolen in Oracle EBS Zero-Day Attack

Bimbo Bakeries USA has confirmed that hackers stole employee data by exploiting a zero-day vulnerability in Oracle’s E-Business Suite (EBS). In...
Read More
USA Bimbo Bakeries Confirms Data Stolen in Oracle EBS Zero-Day Attack

ALERT
Roundcube Webmail fixes 12 security flaws, including zero-click XSS and SSRF bypass

Roundcube Webmail has given security updates for its 1.6 LTS and 1.7 branches. These updates fix 12 problems that could...
Read More
ALERT  Roundcube Webmail fixes 12 security flaws, including zero-click XSS and SSRF bypass

New HOOKEDGE Backdoor Deployed by Hackers in European Espionage

Russian-backed hacker group BlueDelta, also known as APT28, Fancy Bear, and Forest Blizzard, has used a small Windows backdoor called...
Read More
New HOOKEDGE Backdoor Deployed by Hackers in European Espionage

Hackers Exploiting MikroTik RouterOS Flaw Gaining Network Access

Attackers are misusing MikroTik routers through their Secure Shell (SSH) service, which can be accessed from the internet, to take...
Read More
Hackers Exploiting MikroTik RouterOS Flaw Gaining Network Access

CrowdStrike launches SafeMind, the first agentic cybersecurity solution for defenders

CrowdStrike launched CrowdStrike SafeMind, a set of special security models and tools from the CrowdStrike Cyber Superintelligence Lab. The SafeMind...
Read More
CrowdStrike launches SafeMind, the first agentic cybersecurity solution for defenders

Claude, DeepSeek, and Qwen AI agents combinedly used to hit gov.t across Asia

Chinese-speaking hackers have added Claude, Qwen, and DeepSeek to their hacking system to automate cyberattacks on governments and other targets...
Read More
Claude, DeepSeek, and Qwen AI agents combinedly used to hit gov.t across Asia

“IBM Security Verify Access could allow a locally authenticated user to execute malicious scripts from outside of its control sphere,” the company explains.

CVE-2025-36356 is a critical vulnerability rated 9.3 on the CVSS scale. It allows local users to gain root privileges due to incorrect permission handling, giving attackers full administrative control from minimal access.

“IBM Security Verify Access could allow a locally authenticated user to escalate their privileges to root due to execution with more privileges than required,” IBM confirms in its bulletin.

CVE-2025-36354 affects systems open to unauthenticated users, allowing execution of arbitrary commands with lower privileges. It arises from improper validation of user input and, while rated 7.3, still poses a risk for externally accessible systems.

“IBM Security Verify Access could allow an unauthenticated user to execute arbitrary commands with lower user privileges on the system due to improper validation of user supplied input,” according to IBM.

“Security vulnerabilities have been addressed in IBM Security Verify Access 10.0.9.0-IF3 and IBM Verify Identity Access 11.0.1.0-IF1,” the advisory states, emphasizing that organizations running earlier versions remain exposed until updates are applied.

IBM has identified the affected products and versions for both containerized and appliance deployments.

IBM Verify Identity Access (Docker & Appliance): Versions 11.0.0.0 – 11.0.1.0
IBM Security Verify Access (Docker & Appliance): Versions 10.0.0.0 – 10.0.9.0-IF2

These vulnerabilities impact systems that control access and verify identities, so it’s essential to patch them quickly for network security.

IBM has released Fix Packs 10.0.9.0-IF3 for Verify Access and 11.0.1.0-IF1 for Verify Identity Access, accessible via IBM Fix Central and container registries.

For container deployments, administrators can pull the latest versions directly from IBM’s registry:

docker pull icr.io/isva/verify-access:[latest-tag] docker pull icr.io/ivia/verify-access:[latest-tag]

Each tag corresponds to the latest patched release and can be verified on IBM’s official documentation portal.

Check Also

MikroTik

Hackers Exploiting MikroTik RouterOS Flaw Gaining Network Access

Attackers are misusing MikroTik routers through their Secure Shell (SSH) service, which can be accessed …