The Circuitry
THE CIRCUITRYYour one-stop source for all tech news
HOMETODAYNEWSFEEDEVENTS
BOOKMARKS
RSS
© 2026 The Circuitry
About UsSourcesContactCorrectionsPrivacy
  • Today
  • Feed
  • Events
  • Saved
Scroll for more
Verification
VERIFIEDConfidence: HIGH
Source identified
Claims cross-referenced
No discrepancies found
Fact-check summary

Checked against the NVD CVE API and CVE.org records for CVE-2026-16916, CVE-2026-11888, CVE-2026-12109 and CVE-2026-19498 (IBM PSIRT CNA CVSS 3.1 scores 9.1 / 6.4 / 5.5 / 5.9; NVD Primary CVSS 3.1 scores 8.8 / 7.5 / 7.2 / 7.5; affected ranges 10.0-10.0.9.2 and 11.0-11.0.3 incl. containers) and IBM Security Bulletin 7291628 (23 CVEs; fixes 10.0.9.3 / 11.0.3.1; no workarounds). Neither source reports active exploitation.

Sourcing
1source

via IBM

IBM · track record
2Stories
100%Verified
230d
All sources →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
Home/Tech/IBM Security Verify Access: 4 more vulnerabilities disclosed
VERIFIEDBy Xavier Rivera· ·2.5 min read

IBM Security Verify Access: 4 more vulnerabilities disclosed

IBM has disclosed four more flaws in Security Verify Access and Verify Identity Access, including a code execution bug it rates critical at 9.1 (NVD: 8.8). Versions 10.0 to 10.0.9.2 and 11.0 to 11.0.3 are affected. IBM says to upgrade to 10.0.9.3 or 11.0.3.1.

Source:IBM
Post
IBM Security Verify Access: 4 more vulnerabilities disclosed
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
TL;DRAI · 60 sec read

IBM has disclosed four more vulnerabilities in IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3, including container editions. CVE-2026-16916 lets an authenticated attacker run code; IBM rates it 9.1 and NVD rates it 8.8. The others are an information disclosure flaw (IBM 6.4, NVD 7.5), an admin-only stack buffer overflow (IBM 5.5, NVD 7.2) and a denial-of-service bug (IBM 5.9, NVD 7.5). IBM lists no workarounds and says to upgrade to 10.0.9.3 or 11.0.3.1.

IBM has disclosed four more vulnerabilities in IBM Security Verify Access and IBM Verify Identity Access. The most serious, which IBM rates critical, lets an authenticated attacker run arbitrary code. The others are an information disclosure flaw, a stack buffer overflow that only an administrator can reach, and a denial-of-service bug. All four are in IBM's October 7 security bulletin, and the CVE records appeared in the National Vulnerability Database on October 8.

Affected versions. IBM lists IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3, in both the appliance and container editions. All four flaws affect all of those versions.

The fix. IBM's bulletin says to upgrade appliances to IBM Security Verify Access 10.0.9.3 or IBM Verify Identity Access 11.0.3.1. The bulletin also links updated container downloads. IBM lists no workarounds or mitigations and "encourages customers to update their systems promptly."
Remote authenticated attackers can achieve arbitrary code execution.

The four flaws. IBM and NVD give each of the four a different score, so both are listed.
• CVE-2026-16916: a remote, authenticated attacker could run arbitrary code because of a protection mechanism failure. IBM rates it 9.1 (critical). Its vector requires high privileges and marks the scope as changed. NVD rates it 8.8 (high), scoring it with low privileges and unchanged scope.
• CVE-2026-11888: an information disclosure flaw. IBM's bulletin names the IBM Verify Identity Access Snapshot Manager Container, while the CVE record lists all the versions above. IBM rates it 6.4 (medium). NVD rates it 7.5 (high), scoring it as exploitable with no privileges.
From The CircuitryThe Feed — live briefs across tech, all day.See what’s happening →
• CVE-2026-12109: an attacker who has administrative privileges and access to the local management interface could run arbitrary code through an unbounded write to a fixed-size stack buffer. IBM rates it 5.5 (medium). NVD rates it 7.2 (high).
• CVE-2026-19498: a remote attacker could cause a denial of service through uncontrolled recursion. IBM rates it 5.9 (medium). NVD rates it 7.5 (high).
Confidentiality, integrity and availability face complete compromise.

About the scores. IBM's scores are CVSS 3.1 base scores from its bulletin and its entries in the CVE records. NVD added its own CVSS 3.1 scores on October 9 after its analysis. Neither IBM's bulletin nor the NVD records report active exploitation.

The wider bulletin. The same IBM bulletin lists 23 CVEs across both products. Among them are two deserialization flaws IBM rates 9.8 (CVE-2026-78401 and CVE-2026-78406) and the authentication bypass CVE-2026-16823, which The Circuitry covered on October 8. IBM gives the same fixed releases for every CVE in the bulletin. Details are in IBM's security bulletin.
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
This roundup replaces The Circuitry's earlier brief on CVE-2026-19498.

EXPERT TAKE

Security teams should prioritize applying the IBM fix or isolating affected Verify Access instances until patches are deployed.

Why this mattersAI · ~100 words

Tap a lens to see what this story means for you.

Morning Brief

Liked this? The Brief brings you the whole day in tech, verified, every morning.

Two minutes, free forever. What's in The Brief →

Reader-supported
DonateBuy me a coffee →Follow@thecircuitry_ →Follow@thecircuitry.to →
HELP US IMPROVE
From The Circuitry

See what’s happening right now

The Feed runs all day — short, verified briefs the moment they break.

Open the Feed →
From The Circuitry

Follow @thecircuitry_

Every story we publish, as it happens. No noise between.

Follow on X ↗On Bluesky ↗

Reader-supported

The Circuitry is a passion project I've always wanted to build, and I love the work behind it.

Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.

Any contribution is appreciated. If not, no pressure. Thanks for reading.

Buy me a coffee
securityvulnerabilityibm
More fromIBM
  • IBM Patches 40 DataPower Gateway Flaws, Seven Rated Critical

    Tech · 1d
More inTech
  • Modern Warfare 4 DMZ Early Access Opens October 20

    Tech · 2h
  • GlobalFoundries signs $2B TSMC deal for US silicon interposers

    Tech · 15h
  • SpaceX agrees to buy 800 MHz spectrum for Starlink Mobile

    Tech · 18h
SupportThe Work

The Circuitry is reader-supported. If you find the daily brief useful, you can buy me a coffee to keep it going.

Buy a coffee →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →

MORE IN THIS BEAT

All Tech →
  • Tech· 

    IBM Security Verify Access hit by CVE-2026-16823 authentication bypass

    IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 contain authentication bypass flaw CVE-2026-16823. IBM rates it 9.1 (critical); NVD rates it 7.5 (high). IBM says to upgrade to 10.0.9.3 or 11.0.3.1.

  • Tech· 

    IBM Patches 40 DataPower Gateway Flaws, Seven Rated Critical

    IBM has fixed 40 vulnerabilities in DataPower Gateway, seven of them rated critical at CVSS 9.3 to 9.8, including remote code execution bugs and an LDAP flaw that accepts empty passwords for admin access. IBM says to upgrade to 10.5.0.23, 10.6.0.11 or 11.0.0.3.

  • Tech· 

    LobsterAI versions 2026.5.27 to 2026.9.23 contain high-severity directory deletion flaw

    Netease-youdao LobsterAI versions 2026.5.27 through 2026.9.23 contain CVE-2026-108156, a high-severity flaw that enables arbitrary directory deletion via a crafted skill's _meta.json file. The vulnerability carries a CVSS score of 7.1 and requires only that a user install the malicious skill.

  • Tech· 

    PHPNuxBill through 2025.3.20 hit by CVE-2026-108108 auth bypass

    PHPNuxBill through 2025.3.20 is affected by CVE-2026-108108, a CVSS 7.1 authentication bypass in RADIUS CHAP verification. Attackers with a valid username can gain network access and consume customer plans using any password.

  • Tech· 

    Microsoft discloses CVE-2026-83947 in Azure Event Grid

    Microsoft has disclosed CVE-2026-83947, a CVSS 7.7 HIGH spoofing vulnerability in Azure Event Grid caused by missing authorization. Microsoft says it has already fully mitigated the cloud-service flaw and customers have nothing to do.