| Publishing Date | 06.05.2026 |
|---|---|
| Last Update | 06.05.2026 |
| Tracking ID | IBA-2026-09 |
Summary
A vulnerability (CVE-2026-32178) has been disclosed in Microsoft .NET. Improper neutralization of special elements allows an unauthorized attacker to perform spoofing over a network (Source: NVD, published 2026-04-14). The affected .NET component is bundled with several iba products. As a result, the listed products inherit this vulnerability and must be updated. No exploitation targeting iba products is known at this time.
Affected products
This applies to all iba products up to the versions listed below:
- ibaCMC v3.7.1
How do I know that I’m affected?
If you have installed any of the products listed above in a version at or below the one indicated, you are affected.
Solution
With the following versions, the issue has been fixed:
- ibaCMC v3.7.2
Customer Actions
Please install the update as described in the Solution section.
Timeline
| 2026-04-23 | Noted by the Security Team |
| 2026-05-06 | Solution implement in ibaCMC v3.7.2 |
