{"schema_version":1,"title":"IBM Sterling File Gateway vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 12 vulnerabilities in IBM Sterling File Gateway: 0 in the last 7 days and 12 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-75878, was published on 18 September 2026.","url":"https://junglewise.ai/threats/technologies/sterling-file-gateway","json_url":"https://junglewise.ai/threats/technologies/sterling-file-gateway.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/sterling-file-gateway","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":2,"all_time":12,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":3,"last_90_days":12,"last_365_days":12},"latest":[{"cve":"CVE-2026-75878","cvss":9.1,"epss":0.0064,"slug":"cve-2026-75878-ibm-sterling-file-gateway-could-allow-a-remote-attacker-to-bypass","title":"IBM Sterling File Gateway authentication bypass via unvalidated SSO header","severity":"critical","exploited":false,"published_at":"2026-09-18T20:17:21.363+00:00","url":"https://junglewise.ai/threats/cve-2026-75878-ibm-sterling-file-gateway-could-allow-a-remote-attacker-to-bypass"},{"cve":"CVE-2026-19290","cvss":7.5,"epss":0.004,"slug":"cve-2026-19290-ibm-sterling-file-gateway-improper-access-control","title":"IBM Sterling File Gateway improper access control","severity":"high","exploited":false,"published_at":"2026-09-14T21:17:04.767+00:00","url":"https://junglewise.ai/threats/cve-2026-19290-ibm-sterling-file-gateway-improper-access-control"},{"cve":"CVE-2026-19273","cvss":5.4,"epss":0.003,"slug":"cve-2026-19273-ibm-sterling-b2b-integrator-and-file-gateway-improper","title":"IBM Sterling B2B Integrator and File Gateway improper authentication in Dashboard","severity":"medium","exploited":false,"published_at":"2026-09-14T21:17:04.49+00:00","url":"https://junglewise.ai/threats/cve-2026-19273-ibm-sterling-b2b-integrator-and-file-gateway-improper"},{"cve":"CVE-2025-36431","cvss":5.4,"slug":"cve-2025-36431-ibm-sterling-b2b-integrator-and-file-gateway-cross-site-scripting","title":"IBM Sterling B2B Integrator and File Gateway cross-site scripting in Web UI","severity":"medium","exploited":false,"published_at":"2026-07-30T15:16:23.057+00:00","url":"https://junglewise.ai/threats/cve-2025-36431-ibm-sterling-b2b-integrator-and-file-gateway-cross-site-scripting"},{"cve":"CVE-2025-36298","cvss":5.4,"slug":"cve-2025-36298-ibm-sterling-b2b-integrator-xss-in-ebics-server","title":"IBM Sterling B2B Integrator XSS in Ebics server","severity":"medium","exploited":false,"published_at":"2026-07-30T15:16:22.11+00:00","url":"https://junglewise.ai/threats/cve-2025-36298-ibm-sterling-b2b-integrator-xss-in-ebics-server"},{"cve":"CVE-2026-3158","cvss":4.3,"slug":"cve-2026-3158-ibm-sterling-b2b-integrator-information-disclosure-in-dashboard","title":"IBM Sterling B2B Integrator information disclosure in dashboard component","severity":"medium","exploited":false,"published_at":"2026-07-28T20:17:24.823+00:00","url":"https://junglewise.ai/threats/cve-2026-3158-ibm-sterling-b2b-integrator-information-disclosure-in-dashboard"},{"cve":"CVE-2026-3157","cvss":4.3,"slug":"cve-2026-3157-ibm-sterling-b2b-integrator-information-disclosure-in-mailbox","title":"IBM Sterling B2B Integrator information disclosure in mailbox component","severity":"medium","exploited":false,"published_at":"2026-07-28T20:17:24.677+00:00","url":"https://junglewise.ai/threats/cve-2026-3157-ibm-sterling-b2b-integrator-information-disclosure-in-mailbox"},{"cve":"CVE-2026-1918","cvss":4.9,"slug":"cve-2026-1918-ibm-sterling-b2b-integrator-sensitive-information-disclosure-in","title":"IBM Sterling B2B Integrator sensitive information disclosure in logs","severity":"medium","exploited":false,"published_at":"2026-07-28T20:17:24.377+00:00","url":"https://junglewise.ai/threats/cve-2026-1918-ibm-sterling-b2b-integrator-sensitive-information-disclosure-in"},{"cve":"CVE-2026-7769","cvss":8.1,"slug":"cve-2026-7769-ibm-sterling-b2b-integrator-and-sterling-file-gateway-sql","title":"IBM Sterling B2B Integrator and Sterling File Gateway SQL injection","severity":"high","exploited":false,"published_at":"2026-07-28T19:17:41.72+00:00","url":"https://junglewise.ai/threats/cve-2026-7769-ibm-sterling-b2b-integrator-and-sterling-file-gateway-sql"},{"cve":"CVE-2026-7362","cvss":4.3,"slug":"cve-2026-7362-ibm-sterling-b2b-integrator-and-file-gateway-improper-access","title":"IBM Sterling B2B Integrator and File Gateway improper access control","severity":"medium","exploited":false,"published_at":"2026-07-28T19:17:41.587+00:00","url":"https://junglewise.ai/threats/cve-2026-7362-ibm-sterling-b2b-integrator-and-file-gateway-improper-access"},{"cve":"CVE-2026-7775","cvss":5.5,"slug":"cve-2026-7775-ibm-sterling-b2b-integrator-and-file-gateway-stored-xss-in-web-ui","title":"IBM Sterling B2B Integrator and File Gateway stored XSS in Web UI","severity":"medium","exploited":false,"published_at":"2026-07-28T16:20:21.637+00:00","url":"https://junglewise.ai/threats/cve-2026-7775-ibm-sterling-b2b-integrator-and-file-gateway-stored-xss-in-web-ui"},{"cve":"CVE-2026-3482","cvss":5.3,"slug":"cve-2026-3482-ibm-sterling-b2b-integrator-and-file-gateway-auth-bypass","title":"IBM Sterling B2B Integrator and File Gateway auth bypass","severity":"medium","exploited":false,"published_at":"2026-07-22T19:17:03.233+00:00","url":"https://junglewise.ai/threats/cve-2026-3482-ibm-sterling-b2b-integrator-and-file-gateway-auth-bypass"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":8},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":1,"exploited":0,"vulnerabilities":3},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"IBM AIX","slug":"aix","vulnerabilities":106,"url":"https://junglewise.ai/threats/technologies/aix"},{"name":"IBM Langflow","slug":"langflow-oss","vulnerabilities":96,"url":"https://junglewise.ai/threats/technologies/langflow-oss"},{"name":"IBM PowerVM VIOS","slug":"powervm-vios","vulnerabilities":73,"url":"https://junglewise.ai/threats/technologies/powervm-vios"},{"name":"IBM i","slug":"i","vulnerabilities":69,"url":"https://junglewise.ai/threats/technologies/i"},{"name":"IBM WebSphere Application Server","slug":"websphere-application-server","vulnerabilities":62,"url":"https://junglewise.ai/threats/technologies/websphere-application-server"},{"name":"IBM Guardium Data Protection","slug":"guardium-data-protection","vulnerabilities":49,"url":"https://junglewise.ai/threats/technologies/guardium-data-protection"},{"name":"IBM Financial Transaction Manager","slug":"financial-transaction-manager","vulnerabilities":45,"url":"https://junglewise.ai/threats/technologies/financial-transaction-manager"},{"name":"IBM WebSphere Application Server Liberty","slug":"websphere-application-server-liberty","vulnerabilities":37,"url":"https://junglewise.ai/threats/technologies/websphere-application-server-liberty"},{"name":"IBM Datastage On Cloud Pak For Data","slug":"datastage-on-cloud-pak-for-data","vulnerabilities":35,"url":"https://junglewise.ai/threats/technologies/datastage-on-cloud-pak-for-data"},{"name":"IBM Concert","slug":"concert","vulnerabilities":22,"url":"https://junglewise.ai/threats/technologies/concert"},{"name":"IBM Db2 Mirror For I","slug":"db2-mirror-for-i","vulnerabilities":22,"url":"https://junglewise.ai/threats/technologies/db2-mirror-for-i"},{"name":"IBM Mq","slug":"mq","vulnerabilities":22,"url":"https://junglewise.ai/threats/technologies/mq"}],"technology":{"hub":true,"name":"IBM Sterling File Gateway","slug":"sterling-file-gateway","vendor":{"name":"IBM","slug":"ibm","url":"https://junglewise.ai/threats/vendors/ibm"},"aliases":[],"category":"middleware","homepage":"https://www.ibm.com/products/sterling-file-gateway","repo_url":"https://www.ibm.com/products/sterling-file-gateway","description":"A managed file transfer solution for secure high-volume data exchange between organizations.","url":"https://junglewise.ai/threats/technologies/sterling-file-gateway"},"most_severe":[{"cve":"CVE-2026-75878","cvss":9.1,"epss":0.0064,"slug":"cve-2026-75878-ibm-sterling-file-gateway-could-allow-a-remote-attacker-to-bypass","title":"IBM Sterling File Gateway authentication bypass via unvalidated SSO header","severity":"critical","exploited":false,"published_at":"2026-09-18T20:17:21.363+00:00","url":"https://junglewise.ai/threats/cve-2026-75878-ibm-sterling-file-gateway-could-allow-a-remote-attacker-to-bypass"},{"cve":"CVE-2026-7769","cvss":8.1,"slug":"cve-2026-7769-ibm-sterling-b2b-integrator-and-sterling-file-gateway-sql","title":"IBM Sterling B2B Integrator and Sterling File Gateway SQL injection","severity":"high","exploited":false,"published_at":"2026-07-28T19:17:41.72+00:00","url":"https://junglewise.ai/threats/cve-2026-7769-ibm-sterling-b2b-integrator-and-sterling-file-gateway-sql"},{"cve":"CVE-2026-19290","cvss":7.5,"epss":0.004,"slug":"cve-2026-19290-ibm-sterling-file-gateway-improper-access-control","title":"IBM Sterling File Gateway improper access control","severity":"high","exploited":false,"published_at":"2026-09-14T21:17:04.767+00:00","url":"https://junglewise.ai/threats/cve-2026-19290-ibm-sterling-file-gateway-improper-access-control"},{"cve":"CVE-2026-7775","cvss":5.5,"slug":"cve-2026-7775-ibm-sterling-b2b-integrator-and-file-gateway-stored-xss-in-web-ui","title":"IBM Sterling B2B Integrator and File Gateway stored XSS in Web UI","severity":"medium","exploited":false,"published_at":"2026-07-28T16:20:21.637+00:00","url":"https://junglewise.ai/threats/cve-2026-7775-ibm-sterling-b2b-integrator-and-file-gateway-stored-xss-in-web-ui"},{"cve":"CVE-2026-19273","cvss":5.4,"epss":0.003,"slug":"cve-2026-19273-ibm-sterling-b2b-integrator-and-file-gateway-improper","title":"IBM Sterling B2B Integrator and File Gateway improper authentication in Dashboard","severity":"medium","exploited":false,"published_at":"2026-09-14T21:17:04.49+00:00","url":"https://junglewise.ai/threats/cve-2026-19273-ibm-sterling-b2b-integrator-and-file-gateway-improper"},{"cve":"CVE-2025-36431","cvss":5.4,"slug":"cve-2025-36431-ibm-sterling-b2b-integrator-and-file-gateway-cross-site-scripting","title":"IBM Sterling B2B Integrator and File Gateway cross-site scripting in Web UI","severity":"medium","exploited":false,"published_at":"2026-07-30T15:16:23.057+00:00","url":"https://junglewise.ai/threats/cve-2025-36431-ibm-sterling-b2b-integrator-and-file-gateway-cross-site-scripting"},{"cve":"CVE-2025-36298","cvss":5.4,"slug":"cve-2025-36298-ibm-sterling-b2b-integrator-xss-in-ebics-server","title":"IBM Sterling B2B Integrator XSS in Ebics server","severity":"medium","exploited":false,"published_at":"2026-07-30T15:16:22.11+00:00","url":"https://junglewise.ai/threats/cve-2025-36298-ibm-sterling-b2b-integrator-xss-in-ebics-server"},{"cve":"CVE-2026-3482","cvss":5.3,"slug":"cve-2026-3482-ibm-sterling-b2b-integrator-and-file-gateway-auth-bypass","title":"IBM Sterling B2B Integrator and File Gateway auth bypass","severity":"medium","exploited":false,"published_at":"2026-07-22T19:17:03.233+00:00","url":"https://junglewise.ai/threats/cve-2026-3482-ibm-sterling-b2b-integrator-and-file-gateway-auth-bypass"},{"cve":"CVE-2026-1918","cvss":4.9,"slug":"cve-2026-1918-ibm-sterling-b2b-integrator-sensitive-information-disclosure-in","title":"IBM Sterling B2B Integrator sensitive information disclosure in logs","severity":"medium","exploited":false,"published_at":"2026-07-28T20:17:24.377+00:00","url":"https://junglewise.ai/threats/cve-2026-1918-ibm-sterling-b2b-integrator-sensitive-information-disclosure-in"},{"cve":"CVE-2026-3158","cvss":4.3,"slug":"cve-2026-3158-ibm-sterling-b2b-integrator-information-disclosure-in-dashboard","title":"IBM Sterling B2B Integrator information disclosure in dashboard component","severity":"medium","exploited":false,"published_at":"2026-07-28T20:17:24.823+00:00","url":"https://junglewise.ai/threats/cve-2026-3158-ibm-sterling-b2b-integrator-information-disclosure-in-dashboard"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}