Vulnerability intelligence
CVE-2026-14973
IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination.
CVSS Score
9.3
Critical
EPSS — Exploit Probability
0.3%
Riskier than 23% of all CVEs · checked 2026-09-12
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
Patch available
Vendor fix published
1 article across 1 outlet · first covered Jul 29, 2026 · latest Jul 29, 2026
Coverage timeline
-
IBM patches critical Aspera flaws, including RCE bugsecurityonline.info · Jul 29, 2026