OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-75878

CRITICAL · CVSS 9.1 EPSS 0.64%

Source: NVD + CISA KEV + EPSS · Published 2026-09-18 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

IBM Sterling File Gateway is vulnerable to an authentication bypass that allows remote attackers to exploit an unvalidated SSO header, potentially gaining a fully authenticated session. This critical vulnerability poses a significant risk to the confidentiality and integrity of sensitive data managed by the gateway. Organizations using this product should prioritize immediate remediation to mitigate potential unauthorized access.

CVE
CVE-2026-75878
Severity
CRITICAL
CVSS
9.1
EPSS
0.64%

Original NVD Description

IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated session due to improper authentication via an unvalidated SSO header.