CVE-2026-11937
published 2026-08-12CVE-2026-11937: IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through…
PriorityP412low3.1CVSS 3.1
AVNACHPRLUINSUCNINAL
EPSS
0.23%
13.6th percentile
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 and IBM Security Verify Access Container 10.0 through 10.0.9.2 Reverse Proxy in certain configurations is vulnerable to a denial of service attack.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | security_verify_access | — | — |
| ibm | security_verify_access | 10.0 – 10.0.9.2 | — |
| ibm | security_verify_access | 10.0.0 – 10.0.9.2 | — |
| ibm | security_verify_access_container | 10.0 – 10.0.9.2 | — |
| ibm | verify_identity_access | 11.0 – 11.0.3 | — |
| ibm | verify_identity_access_container | 11.0 – 11.0.3 | — |
| ibm | verify_identity_access_container | 11.0.0.0 – 11.0.3.0 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 and IBM Security Verify Access Containe
ghsa_unreviewed·2026-08-12
CVE-2026-11937 [LOW] CWE-416 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 and IBM Security Verify Access Containe
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 and IBM Security Verify Access Container 10.0 through 10.0.9.2 Reverse Proxy in certain configurations is vulnerable to a denial of service attack.
VulDB
IBM Security Verify Access Reverse Proxy denial of service
vuldb·2026-08-12·CVSS 3.1
CVE-2026-11937 [LOW] IBM Security Verify Access Reverse Proxy denial of service
A vulnerability classified as problematic was found in IBM Security Verify Access, Security Verify Access Container, Verify Identity Access and Verify Identity Access Container. This issue affects some unknown processing of the component Reverse Proxy. Such manipulation leads to denial of service.
This vulnerability is listed as CVE-2026-11937. The attack may be performed from remote. There is no available exploit.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-12
Published