securityonline.info 7/29/2026, 8:14:11 AM · external

IBM patches critical Aspera flaws, including RCE bug

IBM patches critical Aspera flaws, including RCE bug
CyberSIXT Evidence Panel
Primary Source ibm.com
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

IBM has patched five vulnerabilities affecting Aspera Faspex 5 and the Aspera Desktop App, identified on July 20, 2026. Of these, four are CVEs with three rated as critical and one high, with the most severe flaw (CVE-2026-14973) having a CVSS score of 9.3, allowing for code execution. The vulnerabilities impact versions 5.0.0 to 5.0.15.4 for Faspex and 1.0.5 to 1.0.19 for the Desktop App.

Key issues include command execution via unquoted shell interpolation and path traversal flaws that can leak files outside designated folders. It is strongly advised to update both products immediately to mitigate potential risks.

View Primary Source Via securityonline.info

Article by CyberSIXT