📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global general Multiple sectors MEDIUM 3h Global general Multiple sectors MEDIUM 3h Global malware Information Technology and Telecommunications HIGH 3h Global phishing,ransomware,general Multiple sectors across Asia-Pacific region HIGH 4h Global supply_chain Government CRITICAL 4h Global malware Telecommunications and Network Infrastructure HIGH 20h Global ransomware Multiple sectors HIGH 1d Global supply_chain Software development, Technology CRITICAL 1d Global vulnerability Web Development and Content Management MEDIUM 2d Global general Government and Policy MEDIUM 2d Global general Multiple sectors MEDIUM 3h Global general Multiple sectors MEDIUM 3h Global malware Information Technology and Telecommunications HIGH 3h Global phishing,ransomware,general Multiple sectors across Asia-Pacific region HIGH 4h Global supply_chain Government CRITICAL 4h Global malware Telecommunications and Network Infrastructure HIGH 20h Global ransomware Multiple sectors HIGH 1d Global supply_chain Software development, Technology CRITICAL 1d Global vulnerability Web Development and Content Management MEDIUM 2d Global general Government and Policy MEDIUM 2d Global general Multiple sectors MEDIUM 3h Global general Multiple sectors MEDIUM 3h Global malware Information Technology and Telecommunications HIGH 3h Global phishing,ransomware,general Multiple sectors across Asia-Pacific region HIGH 4h Global supply_chain Government CRITICAL 4h Global malware Telecommunications and Network Infrastructure HIGH 20h Global ransomware Multiple sectors HIGH 1d Global supply_chain Software development, Technology CRITICAL 1d Global vulnerability Web Development and Content Management MEDIUM 2d Global general Government and Policy MEDIUM 2d
Vulnerabilities

CVE-2026-2862

Medium
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Acces
CWE-444 — Weakness Type
Published: Apr 1, 2026  ·  Modified: Apr 4, 2026  ·  Source: NVD
CVSS v3
5.3
🔗 NVD Official
📄 Description (English)

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 IBM Security Verify could allow a remote attacker to access sensitive information due to an inconsistent interpretation of an HTTP request by a reverse proxy.

🤖 AI Executive Summary

IBM Security Verify products (versions 10.0-10.0.9.1 and 11.0-11.0.2) are vulnerable to HTTP request smuggling attacks that allow remote attackers to bypass reverse proxy security controls and access sensitive information. The vulnerability stems from inconsistent HTTP request interpretation between the reverse proxy and backend application.

📄 Description (Arabic)

تسمح هذه الثغرة للمهاجمين بتجاوز عناصر تحكم الأمان في الوكيل العكسي من خلال استغلال الاختلافات في تفسير طلبات HTTP بين الوكيل والتطبيق الخلفي. يمكن للمهاجمين الوصول إلى بيانات حساسة أو تنفيذ عمليات غير مصرح بها على الأنظمة المتأثرة. تؤثر الثغرة على حاويات وتطبيقات IBM Security Verify في بيئات الإنتاج.

🤖 ملخص تنفيذي (AI)

منتجات IBM Security Verify (الإصدارات 10.0-10.0.9.1 و 11.0-11.0.2) عرضة لهجمات تهريب طلبات HTTP التي تسمح للمهاجمين البعيدين بتجاوز عناصر تحكم أمان وكيل عكسي والوصول إلى معلومات حساسة. ينشأ الثغرة من تفسير غير متسق لطلبات HTTP بين الوكيل العكسي والتطبيق الخلفي.

🤖 AI Intelligence Analysis Analyzed: May 30, 2026 03:00
🇸🇦 Saudi Arabia Impact Assessment
Saudi Relevance: high
🏢 Affected Saudi Sectors
banking government telecom healthcare
🎯 MITRE ATT&CK Techniques
⚖️ Saudi Risk Score (AI)
6.0
/ 10.0
🔧 Remediation Steps (English)
Update IBM Security Verify Identity Access Container and IBM Security Verify Access Container to versions beyond 11.0.2 and 10.0.9.1 respectively. Apply security patches from IBM immediately. Implement strict HTTP request validation and normalization at reverse proxy layer. Monitor for suspicious HTTP request patterns and implement Web Application Firewall (WAF) rules to detect request smuggling attempts.
🔧 خطوات المعالجة (العربية)
قم بتحديث حاويات IBM Security Verify Identity Access و IBM Security Verify Access إلى إصدارات أحدث من 11.0.2 و 10.0.9.1 على التوالي. طبق تصحيحات الأمان من IBM فوراً. نفذ التحقق من صحة طلبات HTTP بشكل صارم وتطبيع على مستوى الوكيل العكسي. راقب أنماط طلبات HTTP المريبة وطبق قواعد جدار حماية تطبيقات الويب (WAF) للكشف عن محاولات تهريب الطلبات.
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
5.1.1 5.1.2 5.2.1
🔵 SAMA CSF
AC-3 AC-6 SI-10
🟡 ISO 27001:2022
A.13.1.1 A.13.2.1 A.14.2.1
📊 CVSS Score
5.3
/ 10.0 — Medium
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredN — None / Network
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityL — Low / Local
IntegrityN — None / Network
AvailabilityN — None / Network
📋 Quick Facts
Severity Medium
CVSS Score5.3
CWECWE-444
EPSS0.04%
Exploit No
Patch ✗ No
Published 2026-04-01
Source Feed nvd
Views 6
🇸🇦 Saudi Risk Score
6.0
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-444
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.