IBM has patched five vulnerabilities affecting Aspera Faspex 5 and the Aspera Desktop App, identified on July 20, 2026. Of these, four are CVEs with three rated as critical and one high, with the most severe flaw (CVE-2026-14973) having a CVSS score of 9.3, allowing for code execution. The vulnerabilities impact versions 5.0.0 to 5.0.15.4 for Faspex and 1.0.5 to 1.0.19 for the Desktop App.
Key issues include command execution via unquoted shell interpolation and path traversal flaws that can leak files outside designated folders. It is strongly advised to update both products immediately to mitigate potential risks.