CVE-2026-75878: IBM Sterling File Gateway

Critical severity, CVSS 9.1. EPSS: 0.6% chance of exploitation in the next 30 days.

IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated session due to improper authentication via an unvalidated SSO header.

Affected products

  • IBM Sterling File Gateway

Published 2026-09-18. Last modified 2026-09-22.