logo

Critical iba Deserialization Vulnerability Exposes ibaPDA and ibaDatCoordinator to RCE (CVE-2026-8024)

ID: b8c6a4a3-931e-57e9-8ff1-dc01f74af20e

STIX ID: report--b8c6a4a3-931e-57e9-8ff1-dc01f74af20e

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-06-19

Date Updated: 2026-06-19

Author: Do Son

...
...

A critical unauthenticated deserialization vulnerability (CVE-2026-8024, CVSSv4 9.3) in ibaPDA and ibaDatCoordinator allows remote attackers to achieve arbitrary code execution and potential privilege escalation by exploiting unsafe use of the .NET BinaryFormatter; CERT@VDE published an advisory and iba released patches (ibaPDA v8.14.0, ibaDatCoordinator v4.0.7), so administrators should apply updates immediately or restrict network exposure as a temporary mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.