CVE-2026-14973: IBM Aspera

Critical severity, CVSS 9.3. EPSS: 0.5% chance of exploitation in the next 30 days.

IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination.

Affected products

  • IBM Aspera: from 1.0.5, up to and including 1.0.19

Published 2026-07-28. Last modified 2026-08-13.