CVE-2026-11980: Code execution in IBM Desktop App
Published Jul 23, 2026
·Updated
IBM Aspera Desktop App 1.0.5 through 1.0.19 can allow arbitrary code execution by loading DLL files at start-up.
Other sources
IBM Aspera Desktop App can allow arbitrary code execution by loading DLL files at start-up.
— IBM
Affected Software
5 affected components
IBM Aspera Desktop App<=1.0.5 - 1.0.19
All of the following
IBM Aspera>=1.0.5<=1.0.19
Any of the following
Apple macOS
Linux Linux kernel
Microsoft Windows
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Aspera Desktop Appto a version that resolves this vulnerability.Fixed in 1.1.0
Event History
Jul 23, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Jul 30, 2026
CVE Published
via MITRE·02:16 PM
Data Sourced
via MITRE·02:16 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-11980?
CVE-2026-11980 has a high severity rating of 7.3.
2
How do I fix CVE-2026-11980?
To mitigate CVE-2026-11980, ensure you update the IBM Aspera Desktop App to a version beyond 1.0.19.
3
What impact does CVE-2026-11980 have on my system?
CVE-2026-11980 can lead to arbitrary code execution, potentially compromising system integrity and confidentiality.
4
Which software is affected by CVE-2026-11980?
CVE-2026-11980 affects IBM Aspera Desktop App versions 1.0.5 through 1.0.19.
5
When was CVE-2026-11980 published?
CVE-2026-11980 was published on July 23, 2026.