PatchSiren cyber security CVE debrief
CVE-2026-8180 IBM CVE debrief
IBM Aspera High-Speed Transfer Endpoint and Server versions 3.7.4 through 4.4.7 Fix Pack 1 contain a denial-of-service vulnerability in the asperahttpd component. An unauthenticated remote attacker can trigger a crash of the asperahttpd service. The vulnerability is classified as CWE-476 (NULL Pointer Dereference) and carries a CVSS 3.1 score of 7.5 (HIGH severity) with network attack vector, low attack complexity, and no required privileges or user interaction. The affected products are enterprise file transfer solutions commonly deployed for high-speed data movement. The IBM PSIRT advisory provides patch guidance. No known exploitation in ransomware campaigns has been reported.
- Vendor
- IBM
- Product
- Aspera High-Speed Transfer Endpoint
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-27
- Original CVE updated
- 2026-06-05
- Advisory published
- 2026-05-27
- Advisory updated
- 2026-06-05
Who should care
Organizations running IBM Aspera High-Speed Transfer Endpoint or Server versions 3.7.4 through 4.4.7 Fix Pack 1, particularly those with asperahttpd exposed to untrusted networks or the internet. Security teams responsible for file transfer infrastructure and availability of critical data movement services.
Technical summary
The asperahttpd component in IBM Aspera High-Speed Transfer Endpoint and Server fails to handle certain input conditions, resulting in a NULL pointer dereference (CWE-476) that causes service termination. The vulnerability is reachable without authentication over the network, making it suitable for automated exploitation. The crash condition affects availability but does not provide confidentiality or integrity compromise.
Defensive priority
HIGH
Recommended defensive actions
- Apply IBM Aspera High-Speed Transfer Endpoint or Server patches to version 4.4.7 Fix Pack 2 or later as indicated in the vendor security advisory
- Restrict network access to asperahttpd service endpoints to authorized hosts only
- Monitor asperahttpd service logs for unexpected crashes or restart events
- Implement network segmentation to limit exposure of Aspera transfer services to untrusted networks
- Review and validate that asperahttpd is not exposed directly to the internet without additional access controls
Evidence notes
Vulnerability description and affected versions derived from NVD record. CVSS vector and CWE classification sourced from NVD weakness data. IBM PSIRT reference confirms vendor acknowledgment. No KEV listing present.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-8180 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-8180
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-8180 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8180
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.ibm.com/support/pages/node/7273615
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.