← Vulnerability feed

Vulnerability record · CVE-2026-8179 · published 27 May 2026

CVE-2026-8179: Ibm aspera high-speed transfer endpoint stack-based buffer overflow vulnerability

Ibm · Aspera High Speed Transfer Endpoint

IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a buffer overflow in the asperahttpd component. This vulnerability could allow an authenticated user to execute arbitrary code on the system.

8.8 CVSS 3.1 High EPSS 0.61% · top 53.0% CWE-121 · Stack-based buffer overflow
8.8CVSS 3.1 base score
0.61%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a buffer overflow in the asperahttpd component. This vulnerability could allow an authenticated user to execute arbitrary code on the system.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-8179 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-8175Ibm aspera high-speed transfer endpoint heap-based buffer overflow vulnerabilityIBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and I…EPSS 0.94%7.5CVE-2026-8180Ibm aspera high-speed transfer endpoint null pointer dereference vulnerabilityIBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and I…EPSS 0.48%7.5CVE-2020-4433Ibm aspera application platform on demand improper input validation vulnerabilityCertain IBM Aspera applications are vulnerable to a stack-based buffer overflow, caused by improper bounds checking. This could allow a remote attack…EPSS 5.1%7.5CVE-2020-4434Ibm aspera application platform on demand classic buffer overflow vulnerabilityCertain IBM Aspera applications are vulnerable to buffer overflow based on the product configuration and valid authentication, which could allow an a…EPSS 2.6%7.5CVE-2020-4435Ibm aspera application platform on demand out-of-bounds write vulnerabilityCertain IBM Aspera applications are vulnerable to arbitrary memory corruption based on the product configuration, which could allow an attacker with …EPSS 1.6%7.5CVE-2020-4436Ibm aspera application platform on demand classic buffer overflow vulnerabilityCertain IBM Aspera applications are vulnerable to buffer overflow after valid authentication, which could allow an attacker with intimate knowledge o…EPSS 3.1%7.5CVE-2020-4432Ibm aspera application platform on demand command injection vulnerabilityCertain IBM Aspera applications are vulnerable to command injection after valid authentication, which could allow an attacker with intimate knowledge…EPSS 3.4%6.5CVE-2026-9035Ibm aspera high-speed transfer endpoint path traversal vulnerabilityIBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and I…EPSS 0.45%

Source: NIST National Vulnerability Database (record CVE-2026-8179), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.