<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:ibm:sterling_file_gateway:6.2.1.0:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aibmsterling_file_gateway6.2.1.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 14 Sep 2026 21:36:20 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aibmsterling_file_gateway6.2.1.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Information Disclosure Vulnerability in IBM Sterling File Gateway</title><link>https://feed.craftedsignal.io/briefs/2026-09-ibm-sterling-info-disclosure/</link><pubDate>Mon, 14 Sep 2026 21:36:20 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-ibm-sterling-info-disclosure/</guid><description>IBM Sterling File Gateway contains an improper access control vulnerability (CVE-2026-19290) that allows remote attackers to obtain sensitive information.</description><content:encoded><![CDATA[<p>IBM Sterling File Gateway is affected by a security vulnerability identified as CVE-2026-19290, which stems from improper access control mechanisms. The vulnerability exists within specific versions of the application, including 6.2.0.0 through 6.2.0.6_1, 6.2.1.0 through 6.2.1.2, and 6.2.2.0 through 6.2.2.1. This flaw permits a remote, unauthenticated attacker to bypass intended access restrictions and gain unauthorized access to sensitive information stored within the system. Given the nature of Sterling File Gateway as a secure file transfer solution, the exposure of data managed by this platform presents a significant risk to organizational confidentiality. The vulnerability carries a CVSS v3.1 base score of 7.5.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows remote attackers to access sensitive data managed by IBM Sterling File Gateway without proper authorization. Organizations utilizing the affected versions in their file transfer workflows are at risk of data exfiltration and loss of regulatory compliance.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the identification of all IBM Sterling File Gateway instances within the environment. Consult the official IBM security bulletin to obtain the patch release or security update that resolves CVE-2026-19290 for your specific deployment version. Ensure all internet-facing instances are restricted from unauthorized network access until the vendor-supplied patches are successfully applied.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>information-disclosure</category><category>ibm</category></item></channel></rss>