cbcvebase.
CVE-2026-13433
published 2026-08-12

CVE-2026-13433: IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to downloading unverified product code when configured to update from an IBM i. A…

PriorityP353critical9.6CVSS 3.1
AVAACLPRNUINSCCHIHAH
EPSS
0.11%
1.6th percentile
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to downloading unverified product code when configured to update from an IBM i. A bad actor could use this vulnerablity to run compromised code on the ACS user's workstation.

Affected

2 ranges
VendorProductVersion rangeFixed in
ibmi_access_client_solutions>= 1.1.2 < 1.1.9.141.1.9.14
ibmi_access_client_solutions1.1.2.0 – 1.1.9.13—
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.