CVE-2026-75878

IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated session due to improper authentication via an unvalidated SSO header.

  • Published Sep 18, 2026
  • CVSS 9.1 critical
  • 0.6% chance of exploitation in the next 30 days (EPSS)

Affected software

In the news

CVE-2026-75878 at the National Vulnerability Database