SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-7364

LOW · CVSS 3.1 EPSS 0.26% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

IBM Verify Identity Access and IBM Security Verify Access products are vulnerable due to an open redirect flaw that could enable remote attackers to conduct phishing attacks by redirecting users to malicious websites. Although the severity is rated low, organizations using affected versions should prioritize remediation to mitigate potential risks associated with phishing attempts. Security teams should assess their deployment of these IBM products to ensure they are not exposed to this vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-7364
Severity
LOW
CVSS
3.1
EPSS
0.26%

Original NVD Description

IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability. An attacker could exploit this vulnerability using a specially crafted request to redirect a victim to arbitrary Web sites.

Related CVEs

Other vulnerabilities affecting the same vendor(s)