CVE-2025-36064: IBM Sterling Connect:express

Medium severity, CVSS 5.9. EPSS: 0.5% chance of exploitation in the next 30 days.

IBM Sterling Connect:Express for Microsoft Windows 3.1.0.0 through 3.1.0.22 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.

Affected products

  • IBM Sterling Connect:express: from 3.1.0.0, before 3.1.0.23 (fixed in 3.1.0.23)

Published 2025-09-22. Last modified 2026-06-17.