CVE-2025-36355: IBM Security Verify Access

High severity, CVSS 8.5. EPSS: 0.2% chance of exploitation in the next 30 days.

IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow a locally authenticated user to execute malicious scripts from outside of its control sphere.

Affected products

  • IBM Security Verify Access: from 10.0.0.0, before 10.0.9.0 (fixed in 10.0.9.0); version 10.0.9.0 only
  • IBM Security Verify Access Docker: from 10.0.0.0, before 10.0.9.0 (fixed in 10.0.9.0); version 10.0.9.0 only
  • IBM Verify Identity Access: from 11.0.0.0, before 11.0.1.0 (fixed in 11.0.1.0); version 11.0.1.0 only
  • IBM Verify Identity Access Docker: from 11.0.0.0, before 11.0.1.0 (fixed in 11.0.1.0); version 11.0.1.0 only

Published 2025-10-06. Last modified 2026-06-17.