{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/aspera-enterprise-webapps-1.0.0-through-1.0.5/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ibm:aspera_enterprise_webapps:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-75777"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Aspera Enterprise WebApps (1.0.0 through 1.0.5)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["IBM"],"content_html":"\u003cp\u003eIBM Aspera Enterprise WebApps versions 1.0.0 through 1.0.5 contain a security flaw that permits a local attacker with access to the application container to escape its security boundaries. The vulnerability arises because the container runtime environment permits unrestricted system calls (syscalls) that should be blocked by standard container hardening practices. By invoking these prohibited system calls, an attacker can interact directly with the underlying host kernel, potentially bypassing container isolation. This vulnerability poses a significant risk to host integrity in multi-tenant or shared-infrastructure environments where Aspera Enterprise WebApps is deployed.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows a local attacker to escape the container environment, gaining unauthorized access to the host operating system. This could lead to full system compromise, data exfiltration from the host, or lateral movement within the network. The scope of impact is limited to organizations running the vulnerable 1.0.0 through 1.0.5 versions of the software in containerized environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate IBM Aspera Enterprise WebApps to the latest available version that patches CVE-2026-75777.\u003c/li\u003e\n\u003cli\u003eAudit container security configurations to restrict syscalls via Seccomp profiles or AppArmor/SELinux policies.\u003c/li\u003e\n\u003cli\u003eApply the principle of least privilege by running containers with non-root users where possible, limiting the potential impact of an escape.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-10T23:10:54Z","date_published":"2026-09-10T23:10:54Z","id":"https://feed.craftedsignal.io/briefs/2026-09-ibm-aspera-escape/","summary":"IBM Aspera Enterprise WebApps versions 1.0.0 through 1.0.5 are susceptible to a container escape vulnerability via unrestricted system calls, potentially allowing a local attacker to gain unauthorized host access.","title":"Container Escape Vulnerability in IBM Aspera Enterprise WebApps","url":"https://feed.craftedsignal.io/briefs/2026-09-ibm-aspera-escape/"}],"language":"en","title":"CraftedSignal Threat Feed - Aspera Enterprise WebApps (1.0.0 Through 1.0.5)","version":"https://jsonfeed.org/version/1.1"}