SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-14959

CRITICAL · CVSS 9.1 EPSS 1.04%

Source: NVD + CISA KEV + EPSS · Published 2026-07-28 · Last synced 2026-08-27

CyberRota Analysis

AI-Generated

IBM Aspera Faspex versions 5.0.0 through 5.0.15.4 are vulnerable to a critical shell command injection flaw that allows remote authenticated attackers to execute arbitrary code on the affected systems. This vulnerability poses a significant risk to the confidentiality, integrity, and availability of the data managed by these applications. Organizations using these specific versions should prioritize immediate remediation to mitigate potential exploitation.

CVE
CVE-2026-14959
Severity
CRITICAL
CVSS
9.1
EPSS
1.04%

Original NVD Description

IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to shell command injection.

Related CVEs

Other vulnerabilities affecting the same vendor(s)