Skip to main navigation Skip to main content Skip to page footer

CVE-2026-32178 - .NET Spoofing Vulnerability in Bundled Microsoft Components

Security Advisories IBA-2026-09

Grüner Hintergrund mit kreisförmigem digitalem Interface-Design.
Publishing Date 06.05.2026
Last Update 06.05.2026
Tracking IDIBA-2026-09

Summary

A vulnerability (CVE-2026-32178) has been disclosed in Microsoft .NET. Improper neutralization of special elements allows an unauthorized attacker to perform spoofing over a network (Source: NVD, published 2026-04-14). The affected .NET component is bundled with several iba products. As a result, the listed products inherit this vulnerability and must be updated. No exploitation targeting iba products is known at this time.

Affected products

This applies to all iba products up to the versions listed below:

  • ibaCMC v3.7.1

How do I know that I’m affected?

If you have installed any of the products listed above in a version at or below the one indicated, you are affected.

Solution

With the following versions, the issue has been fixed:

  • ibaCMC v3.7.2

Customer Actions

Please install the update as described in the Solution section.

Timeline

2026-04-23Noted by the Security Team
2026-05-06Solution implement in ibaCMC v3.7.2
Zurück zur Übersicht

Was möchten Sie heute machen?

Mit der Auswahl des Landes wird meine Anfrage an die zuständige Landesniederlassung der iba AG für Vertrieb und Support weitergeleitet.Datenschutz­erklärung