{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/sterling-file-gateway-6.2.0.0---6.2.0.6_1-6.2.1.0---6.2.1.2-6.2.2.0---6.2.2.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ibm:sterling_file_gateway:6.2.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:sterling_file_gateway:6.2.1.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:sterling_file_gateway:6.2.2.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-19290"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Sterling File Gateway (6.2.0.0 - 6.2.0.6_1, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","information-disclosure","ibm"],"_cs_type":"advisory","_cs_vendors":["IBM"],"content_html":"\u003cp\u003eIBM Sterling File Gateway is affected by a security vulnerability identified as CVE-2026-19290, which stems from improper access control mechanisms. The vulnerability exists within specific versions of the application, including 6.2.0.0 through 6.2.0.6_1, 6.2.1.0 through 6.2.1.2, and 6.2.2.0 through 6.2.2.1. This flaw permits a remote, unauthenticated attacker to bypass intended access restrictions and gain unauthorized access to sensitive information stored within the system. Given the nature of Sterling File Gateway as a secure file transfer solution, the exposure of data managed by this platform presents a significant risk to organizational confidentiality. The vulnerability carries a CVSS v3.1 base score of 7.5.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows remote attackers to access sensitive data managed by IBM Sterling File Gateway without proper authorization. Organizations utilizing the affected versions in their file transfer workflows are at risk of data exfiltration and loss of regulatory compliance.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification of all IBM Sterling File Gateway instances within the environment. Consult the official IBM security bulletin to obtain the patch release or security update that resolves CVE-2026-19290 for your specific deployment version. Ensure all internet-facing instances are restricted from unauthorized network access until the vendor-supplied patches are successfully applied.\u003c/p\u003e\n","date_modified":"2026-09-14T21:36:20Z","date_published":"2026-09-14T21:36:20Z","id":"https://feed.craftedsignal.io/briefs/2026-09-ibm-sterling-info-disclosure/","summary":"IBM Sterling File Gateway contains an improper access control vulnerability (CVE-2026-19290) that allows remote attackers to obtain sensitive information.","title":"Information Disclosure Vulnerability in IBM Sterling File Gateway","url":"https://feed.craftedsignal.io/briefs/2026-09-ibm-sterling-info-disclosure/"}],"language":"en","title":"CraftedSignal Threat Feed - Sterling File Gateway (6.2.0.0 - 6.2.0.6_1, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1)","version":"https://jsonfeed.org/version/1.1"}