SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-14958

CRITICAL · CVSS 9.1 EPSS 0.52%

Source: NVD + CISA KEV + EPSS · Published 2026-07-28 · Last synced 2026-08-27

CyberRota Analysis

AI-Generated

IBM Aspera Faspex versions 5.0.0 through 5.0.15.4 are vulnerable to a critical remote code execution flaw caused by unquoted shell interpolation, allowing authenticated attackers to execute arbitrary code on the affected systems. Organizations using these versions should prioritize patching to mitigate the risk of exploitation, as the severity of this vulnerability could lead to significant data breaches or system compromise. Immediate action is recommended for environments where Faspex is deployed.

CVE
CVE-2026-14958
Severity
CRITICAL
CVSS
9.1
EPSS
0.52%

Original NVD Description

IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation.

Related CVEs

Other vulnerabilities affecting the same vendor(s)