


Perceptive Security
SOC/SIEM Consultancy

IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to shell command injection.
Published:
27 juli 2026 om 22:00:00
Alert date:
28 juli 2026 om 22:02:06
Source:
nvd.nist.gov
Enterprise Applications, Web Technologies
CVE-2026-14959 affects IBM Aspera Faspex 5 versions 5.0.0 through 5.0.15.4. The vulnerability allows a remote authenticated attacker to execute arbitrary code on the affected system via shell command injection. The flaw requires authentication, meaning an attacker must have valid credentials to exploit it. IBM has issued an advisory with remediation guidance. The severity is rated high due to the potential for full system compromise through remote code execution. Organizations using affected versions of IBM Aspera Faspex 5 should apply patches immediately.
Technical details
Mitigation steps:
Affected products:
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
