CVE-2025-36087: IBM Security Verify Access
Critical severity, CVSS 9.8. EPSS: 0.3% chance of exploitation in the next 30 days.
IBM Security Verify Access 10.0.0 through 10.0.9, 11.0.0, IBM Verify Identity Access Container 10.0.0 through 10.0.9, and 11.0.0, under certain configurations, contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
Affected products
- IBM Security Verify Access: from 10.0.0, up to and including 10.0.9
- IBM Verify Identity Access: version 11.0.0 only
Published 2025-10-13. Last modified 2026-06-17.