<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cve-2026-18872 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-18872/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 22 Sep 2026 22:39:56 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-18872/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Security Misconfiguration in IBM Financial Transaction Manager for RedHat OpenShift</title><link>https://feed.craftedsignal.io/briefs/2026-09-ibm-ftm-security-misconfiguration/</link><pubDate>Tue, 22 Sep 2026 22:39:56 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-ibm-ftm-security-misconfiguration/</guid><description>IBM Financial Transaction Manager for RedHat OpenShift is vulnerable to an improper configuration of HTTP method-based security constraints, allowing remote unauthenticated attackers to bypass access controls.</description><content:encoded><![CDATA[<p>IBM Financial Transaction Manager (FTM) for RedHat OpenShift suffers from a critical security misconfiguration related to the enforcement of HTTP method-based security constraints. This vulnerability, identified as CVE-2026-17635, permits a remote, unauthenticated attacker to manipulate HTTP requests to evade intended access control mechanisms. By utilizing specific HTTP methods that were not properly restricted during the application's configuration, an attacker can perform unauthorized actions within the transaction management environment. Given the nature of this software in processing financial transactions, the successful exploitation of this vulnerability poses a significant risk to the integrity and confidentiality of high-value transaction data. Defenders should prioritize auditing the configuration of their FTM instances and monitoring for unusual HTTP method usage directed at the application API.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability allows unauthorized access to core transaction management functions, which could result in unauthorized transaction initiation, modification, or exposure of sensitive financial data. Failure to remediate this misconfiguration within the production environment may lead to severe operational and financial disruption, as well as a compromise of regulatory compliance requirements associated with financial transaction processing systems.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the immediate audit of all IBM Financial Transaction Manager for RedHat OpenShift deployments for security misconfigurations.
Implement strict HTTP request filtering at the web application firewall or OpenShift ingress level to ensure only authorized methods are permitted for specific API endpoints.
Ensure that security patches or configuration updates provided by IBM for CVE-2026-17635 are applied to all instances.
Monitor web server logs for HTTP methods that deviate from the expected traffic patterns for specific application paths.</p>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>web-vulnerability</category><category>security-misconfiguration</category><category>financial-services</category><category>cve-2026-17635</category><category>cross-site-scripting</category><category>cve-2026-18872</category><category>ai-security</category><category>rag-poisoning</category><category>cve-2026-18875</category></item></channel></rss>