CVE-2025-36255: IBM DS8900F Firmware

High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.

IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authenticated user to create a user with privileged user roles due to improper privileged defined with unsafe actions.

Affected products

  • IBM DS8900F Firmware: from 89.40.83.0, up to and including 89.44.25.0
  • IBM DS8A00 Firmware: from 10.1.3.0, up to and including 10.11.35.0

Published 2026-08-19. Last modified 2026-09-29.