IBM has released security updates to fix 22 vulnerabilities across its Verify Access and related identity management products. The roundup lists a total of six CVEs, with five rated Critical and one High. The highest-severity issue is CVE-2026-78401, scored 9.8 CVSSv3, with other notable flaws including CVE-2026-78406 (9.8), CVE-2026-16916 (9.1), CVE-2026-16823 (9.1), CVE-2026-19491 (9.1) and CVE-2026-17189 (8.2). At the time of reporting, there was no confirmed exploitation in the wild.
The article explains that the most dangerous flaw involves untrusted data deserialization, potentially allowing a remote unauthenticated attacker to execute arbitrary code on impacted systems. Additional high-severity issues enable authentication bypass via manipulated HTTP requests, along with other problems such as local code execution via reflected cross-site scripting and possible denial of service from uncontrolled recursion.
The piece notes that while there is no public PoC and no confirmed active exploitation yet, threat actors rapidly study patches, so rapid remediation is advised.
Affected software versions include IBM Security Verify Access 10.0 through 10.0.9[.]2 and IBM Verify Identity Access 11.0 through 11.0.3. Administrators are urged to upgrade promptly. Specifically, users on version 11 should install IBM Verify Identity Access v11.0.3.1, while older deployments should move to IBM Security Verify Access v10.0.9.3. The article stresses applying these fixes before normal operations resume to minimise disruption. 9 October 2026.