PULSE
FEED
ransomsilentransomgroup reclama a O'Hagan Meyer · Professional Servicesransomnetrunner reclama a Mid Atlantic Gynecologic Oncology and Pelvic Surgery Associates · US · Healthcareransomumbra reclama a SOCOCO · FR · Technologyransomeclipse reclama a dipecarr.com.br · BR · Manufacturingransomqilin reclama a MCM Telecom · MX · Technologyransomsilentransomgroup reclama a Baker McKenzie · US · Professional Servicesransomumbra reclama a Manipal Academy of Higher Edu · IN · Educationransomumbra reclama a IIT Roorkee · IN · Educationransomumbra reclama a FSE, Cairo University · EG · Educationransompayload reclama a Boullard Musique · FR · Retail & E-Commerceransomeclipse reclama a simplexengg.in · IN · Manufacturingransomeclipse reclama a sanjoseattorneys.com · US · Professional Servicesransomsilentransomgroup reclama a Andersen Group Inc. · Professional Servicesransomeclipse reclama a DIPECARR · BR · Otherransomsilentransomgroup reclama a O'Hagan Meyer · Professional Servicesransomnetrunner reclama a Mid Atlantic Gynecologic Oncology and Pelvic Surgery Associates · US · Healthcareransomumbra reclama a SOCOCO · FR · Technologyransomeclipse reclama a dipecarr.com.br · BR · Manufacturingransomqilin reclama a MCM Telecom · MX · Technologyransomsilentransomgroup reclama a Baker McKenzie · US · Professional Servicesransomumbra reclama a Manipal Academy of Higher Edu · IN · Educationransomumbra reclama a IIT Roorkee · IN · Educationransomumbra reclama a FSE, Cairo University · EG · Educationransompayload reclama a Boullard Musique · FR · Retail & E-Commerceransomeclipse reclama a simplexengg.in · IN · Manufacturingransomeclipse reclama a sanjoseattorneys.com · US · Professional Servicesransomsilentransomgroup reclama a Andersen Group Inc. · Professional Servicesransomeclipse reclama a DIPECARR · BR · Other
← Todos los CVEs
CVE Watch8 oct 2026

CVE-2026-19493

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to perform

CVSS

7.5

Alto

EPSS

—

KEV

—

Exploit Today

0

0-100

Publicado: 8 oct 2026 · Última mod.: 8 oct 2026 · CWE-22

EPSS · 30d

Sin historial EPSS suficiente todavía.

Descripción técnica

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to perform an arbitrary file write due to path traversal.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-842478.1 ALT
—
——0IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability.9h
CVE-2026-829008.1 ALT
—
——0IBM Guardium Data Protection 12.2.2, and 12.1 could allow a remote attacker to delete arbitrary files due to improper limitation of a pathname to a restricted directory.9h
CVE-2026-758759.8 CRÍ
—
——0IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to path traversal.9h
CVE-2026-107716—
—
——0Banks generates meaningful LLM prompts using a simple template language. Prior to 2.5.1, Banks DirectoryPromptRegistry does not reject symbolic links for index.json or discovered and existing .jinja prompt files. In an application where untrusted users can influence a prompt directory, DirectoryPromptRegistry._scan() and DirectoryPromptRegistry.get() can follow a link outside the registry root and disclose a file, while DirectoryPromptRegistry.set(), DirectoryPromptRegistry._save(), and DirectoryPromptRegistry._load() can read or overwrite an external link target. The issue requires attacker influence over the registry directory or its extracted contents. This issue is fixed in version 2.5.1.9h
CVE-2026-842757.5 ALT
—
——0IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the GIM file-upload functionality. An unauthenticated attacker could exploit this vulnerability to write arbitrary files to the Collector.10h
CVE-2026-1073777.5 ALT
—
——0datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.81.0, an attacker-controlled Protobuf schema can supply absolute or parent-directory paths captured by WEAK_IMPORT_PATTERN and consumed by _write_missing_weak_imports in src/datamodel_code_generator/parser/protobuf.py. Exploitation requires a victim or automated job to process the attacker-controlled schema with Protobuf input support, which requires the grpcio-tools package. The paths escape the weak_imports temporary directory before protoc runs, allowing creation of directory trees and new files or overwrite of existing writable files with a generated Protobuf syntax declaration. The effect persists when later Protobuf compilation fails. The written content is limited to a proto2 or proto3 syntax declaration, and direct arbitrary code execution has not been demonstrated. This issue is fixed in version 0.81.0.13h