CVE-2025-36326: IBM Cognos Controller

High severity, CVSS 7.5. EPSS: 0.2% chance of exploitation in the next 30 days.

IBM Cognos Controller 11.0.0 through 11.0.1, and IBM Controller 11.1.0 through 11.1.1 could allow an attacker to obtain sensitive information due to the use of hardcoded cryptographic keys for signing session cookies.

Affected products

  • IBM Cognos Controller: from 11.0.0, up to and including 11.0.1
  • IBM Controller: from 11.1.0, up to and including 11.1.1

Published 2025-09-26. Last modified 2026-06-17.