AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-12628

CRITICAL · CVSS 9.1 EPSS 0.36%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-06-22 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.1. It affects Windows. It may be remotely exploitable. Exploitation may require the attacker to be authenticated.

CVE
CVE-2026-12628
Severity
CRITICAL
CVSS
9.1
EPSS
0.36%
Windows

Original NVD Description

IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 through 8.2.1.0 could allow a remote attacker to bypass authentication due to the use of a hardcoded credential in the FlashCopy Manager (FCM) authentication mechanism. The application contains a static credential embedded in multiple authentication code paths, and does not properly validate authentication responses, which may allow an unauthenticated attacker to establish a trusted session and access protected services. This vulnerability affects client components across multiple versions and may allow an attacker to impersonate legitimate clients, potentially leading to unauthorized access to system resources.

Related CVEs

Other vulnerabilities affecting the same vendor(s)