CVE-2025-36074: IBM Security Verify Directory

High severity, CVSS 7.2. EPSS: 0.3% chance of exploitation in the next 30 days.

IBM Security Verify Directory (Container) 10.0.0 through 10.0.0.3 IBM Security Verify Directory could be vulnerable to malicious file upload by not validating file type. A privileged user could upload malicious files into the system that can be sent to victims for performing further attacks against the system.

Affected products

  • IBM Security Verify Directory: from 10.0.0, up to and including 10.0.3

Published 2026-04-23. Last modified 2026-10-07.