Skip to content
Threat Feed

Tag

Ibm

29 briefs RSS
critical advisory

Critical Deserialization Vulnerability in IBM webMethods Integration

IBM webMethods Integration (on-premises) versions 10.11 and 10.15 contain a critical deserialization vulnerability (CVE-2026-12118) that enables unauthenticated remote code execution.

webMethods Integration remote-code-execution deserialization ibm cve-2026-12118
1t 1c
critical advisory

Unauthenticated Remote Code Execution in IBM Langflow OSS

IBM Langflow OSS versions 1.0.0 through 1.10.1 are susceptible to unauthenticated remote code execution due to improper sanitization of environment variables in the MCP stdio launcher.

Langflow OSS remote-code-execution cve-2026-12940 ibm langflow code-injection vulnerability rce
3t 1c
medium threat

IBM WebSphere Application Server Liberty: Multiple Vulnerabilities Enable Denial of Service

Multiple vulnerabilities exist in IBM WebSphere Application Server Liberty that an attacker can exploit to perform a Denial of Service attack.

exploited WebSphere Application Server Liberty denial-of-service vulnerability ibm websphere
1t
high advisory

IBM WebSphere Application Server Liberty Path-Segment Injection Vulnerability (CVE-2026-15280)

A path-segment injection vulnerability (CVE-2026-15280) in the collective routing mechanism of IBM WebSphere Application Server - Liberty versions 17.0.0.3 through 26.0.0.8 ND Collective Controller allows an unauthenticated attacker to inject arbitrary path segments, potentially leading to information disclosure.

WebSphere Application Server - Liberty 17.0.0.3 +45 vulnerability path-segment-injection information-disclosure websphere ibm
1c
high threat

CVE-2026-14996: IBM Aspera Faspex 5 Session Management Vulnerability

CVE-2026-14996 details a high-severity vulnerability (CVSS v3.1 8.2, CWE-613) in IBM Aspera Faspex 5 versions 5.0.0 through 5.0.15.4 that allows unauthenticated, remote attackers to exploit insufficient session management, leading to high confidentiality impact and low integrity impact.

exploited Aspera Faspex 5 +1 vulnerability session-management IBM cve
1t 1c
critical advisory

IBM Aspera Desktop App Path Traversal Vulnerability (CVE-2026-14973)

The IBM Aspera Desktop App (versions 1.0.5 through 1.0.19) is affected by a path traversal vulnerability (CWE-22) which allows files to be written outside of the user's selected download destination, leading to high integrity and confidentiality impacts through arbitrary file write operations, and requires user interaction to exploit.

Aspera Desktop App +1 vulnerability path-traversal ibm aspera cve critical-vulnerability
1t 1c
critical advisory

CVE-2026-14959: IBM Aspera Faspex 5 Remote Code Execution via Shell Command Injection

A critical vulnerability, CVE-2026-14959, in IBM Aspera Faspex 5 (versions 5.0.0 through 5.0.15.4) allows a remote authenticated attacker to execute arbitrary code due to a shell command injection flaw, potentially leading to full system compromise and significant data loss or service disruption.

Aspera Faspex 5 vulnerability command-injection rce remote-code-execution ibm
2t 1c
high advisory

IBM DB2: Multiple Vulnerabilities

Multiple vulnerabilities in IBM DB2 allow an attacker to perform a Denial of Service (DoS) attack and execute arbitrary code, which could lead to system disruption or full compromise.

DB2 vulnerability rce dos database ibm
2t
high advisory

IBM Engineering AI Hub Information Disclosure via URL Session Tokens (CVE-2026-15322)

A remote attacker can exploit CVE-2026-15322 in IBM Engineering AI Hub versions 1.0.0, 1.1.0, and 1.2.0 to obtain sensitive session tokens exposed in URLs, potentially leading to unauthorized access and information disclosure.

Engineering AI Hub 1.0.0 +2 vulnerability information-disclosure session-token ibm cve
1t 1c
critical advisory

IBM Langflow OSS Remote Code Execution via Deserialization

IBM Langflow OSS versions 1.0.0 through 1.10.0 contain a critical deserialization vulnerability (CVE-2026-8476) in its disk-based caching mechanism, which uses Python's unsafe `pickle.loads()` function without proper validation, allowing attackers to process malicious pickle payloads and achieve arbitrary code execution with the privileges of the Langflow server process, leading to complete system compromise.

Langflow OSS 1.0.0 +13 remote-code-execution deserialization python langflow web-vulnerability rce authentication-bypass critical-vulnerability +7
1r 5t 7c 1i
low advisory

IBM PowerVM Novalink Vulnerable to Denial of Service via Specially-Crafted Request

IBM PowerVM Novalink is vulnerable to CVE-2026-9171, a denial-of-service attack where a remote unauthenticated attacker can send a specially-crafted request to cause the server to consume excessive memory resources, leading to system unavailability.

PowerVM Novalink 2.2.02.2.12.2.1.1 +1 denial-of-service vulnerability IBM PowerVM Novalink
1t 1c 1i
critical advisory

IBM Langflow OSS Code Injection Vulnerability in ToolGuard (CVE-2026-9135)

An authenticated attacker can exploit CVE-2026-9135, a code injection vulnerability in IBM Langflow OSS versions 1.0.0 through 1.9.2, to bypass security controls and achieve arbitrary Python code execution on the backend through unvalidated dynamic CodeInput fields in the ToolGuard integration, potentially escalating privileges via cross-tenant flow manipulation.

Langflow OSS code-injection vulnerability rce langflow hard-coded-credentials ibm
3t 1c
critical advisory

IBM Langflow OSS Improper Authentication Vulnerability

A remote attacker can gain full administrative access to IBM Langflow OSS versions 1.0.0 through 1.10.0 by exploiting an improper authentication vulnerability. The /api/v1/login/auto_login endpoint, when the default AUTO_LOGIN configuration is enabled, issues long-lived superuser bearer tokens without requiring authentication. This allows an unauthenticated network attacker to obtain these tokens and achieve superuser privileges. Additionally, permissive Cross-Origin Resource Sharing (CORS) settings could expose these tokens to unintended origins, exacerbating the risk.

Langflow OSS vulnerability web-application api-exploitation improper-authentication cve privilege-escalation code-injection critical-vulnerability +4
2r 5t 3c
high advisory

CVE-2026-3144 - IBM API Connect Default Credentials Vulnerability

IBM API Connect versions 12.1.0.0 through 12.1.0.3 are vulnerable to unauthorized access due to the use of default credentials, allowing an attacker to gain initial access to the application before the system enforces a credential update.

API Connect +3 vulnerability-exploitation default-credentials ibm api-connect initial-access
1t 1c
high advisory

Multiple Vulnerabilities in IBM Operational Decision Manager

Multiple vulnerabilities in IBM Operational Decision Manager can be exploited by a remote, unauthenticated attacker, allowing them to bypass security restrictions, achieve remote code execution, and cause a denial of service condition.

IBM Operational Decision Manager vulnerability rce dos ibm security-bypass
4t
high advisory

IBM WebSphere Application Server: Authenticated Remote Action Execution Vulnerability

A vulnerability in IBM WebSphere Application Server allows a remote, authenticated attacker to execute arbitrary actions on the server, potentially leading to a compromise of the host system.

WebSphere Application Server websphere vulnerability rce ibm server authenticated-access
1t
high advisory

CVE-2026-8179 - IBM Aspera High-Speed Transfer Endpoint and Server Buffer Overflow

IBM Aspera High-Speed Transfer Endpoint and Server 3.7.4 through 4.4.7 Fix Pack 1 are vulnerable to a buffer overflow in the asperahttpd component, potentially allowing an authenticated user to execute arbitrary code.

Aspera High-Speed Transfer Endpoint +1 buffer-overflow rce ibm aspera
2r 1t 1c
medium advisory

IBM Langflow OSS Uncontrolled Resource Consumption Denial-of-Service (CVE-2026-7528)

IBM Langflow OSS versions 1.0.0 through 1.9.0 are vulnerable to a denial-of-service (DoS) attack due to uncontrolled resource consumption as tracked by CVE-2026-7528.

Langflow OSS dos cve-2026-7528 ibm
2r 1t 1c
critical advisory

IBM Controller Hard-Coded Credentials Vulnerability (CVE-2026-5065)

IBM Controller versions 11.0.1, 11.1.0, 11.1.1, and 11.1.2 are vulnerable to hard-coded credentials (CVE-2026-5065), potentially allowing unauthorized access and control of the application.

Controller 11.0.1 +3 cve credential-access ibm hardcoded-credentials
2r 1t 1c
high advisory

IBM QRadar Vulnerability CVE-2024-56462 Allows Privilege Escalation via Malicious Backup Upload

IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 002 is vulnerable to CVE-2024-56462, enabling a privileged user to upload a malicious backup archive that, upon restoration, leads to unauthorized access to the underlying operating system.

QRadar 7.5.0 +1 privilege-escalation cve ibm
2r 1t 1c
high advisory

CVE-2026-4051: IBM Engineering Lifecycle Management Remote Code Execution

IBM Engineering Lifecycle Management 7.0.3 through Interim Fix 021, 7.1.0 through Interim Fix 009, and 7.2.0 through Interim Fix 001 could allow an attacker with administrative privileges to execute remote code due to an exposed method that is not properly restricted, potentially leading to complete system compromise.

Engineering Lifecycle Management 7.0.3 +2 cve rce ibm
2r 1t 1c
critical advisory

CVE-2026-3660: IBM Engineering Lifecycle Management Unauthenticated Remote Access

IBM Engineering Lifecycle Management versions 7.0.3 through Interim Fix 021, 7.1.0 through Interim Fix 009, and 7.2.0 through Interim Fix 001 are vulnerable to an unauthenticated remote attacker who can update server property files, leading to unauthorized access to the application.

Engineering Lifecycle Management cve cve-2026-3660 ibm unauthenticated access property file modification
2r 1t 1c
medium threat

CVE-2026-8856 - IBM HTTP Server Denial of Service Vulnerability

IBM HTTP Server 8.5 and 9.0 is vulnerable to a denial of service (DoS) in configurations where an attacker possesses write access to server configuration files, as tracked by CVE-2026-8856.

HTTP Server 8.5 +1 cve-2026-8856 dos ibm
2r 1t 1c
high threat

CVE-2026-8855: IBM HTTP Server RCE and DoS via TLS Mutual Authentication

IBM HTTP Server 8.5 and 9.0 are vulnerable to remote code execution and denial of service in configurations utilizing TLS mutual authentication (client authentication).

HTTP Server 8.5 +1 cve rce dos tls ibm
2r 2t 1c
critical advisory

IBM Semeru Runtime Code Execution Vulnerability

A remote, anonymous attacker can exploit a vulnerability in IBM Semeru Runtime and IBM DB2 to execute arbitrary program code.

code-execution vulnerability ibm
2r 1t
medium advisory

IBM Verify and Security Verify Access Container Server-Side Request Forgery Vulnerability (CVE-2026-1343)

CVE-2026-1343 allows an attacker to contact internal authentication endpoints protected by the Reverse Proxy in IBM Verify Identity Access Container and IBM Security Verify Access Container.

cve cve-2026-1343 ssrf ibm
2r 2t 1c
critical advisory

IBM Verify Access and Security Verify Access Container Privilege Escalation (CVE-2026-1346)

A locally authenticated user can escalate privileges to root on vulnerable IBM Verify Identity Access Container and IBM Security Verify Access Container installations due to the execution of processes with unnecessary privileges, as tracked by CVE-2026-1346.

privilege-escalation cve-2026-1346 ibm
2r 1t 1c
high advisory

IBM App Connect Enterprise Multiple Vulnerabilities

A remote, anonymous attacker can exploit multiple vulnerabilities in IBM App Connect Enterprise to cause a denial-of-service condition or bypass security measures, enabling cross-site scripting attacks.

vulnerability dos xss ibm
2r 2t
critical advisory

IBM Tivoli Netcool/OMNIbus Multiple Vulnerabilities

An anonymous remote attacker can exploit multiple vulnerabilities in IBM Tivoli Netcool/OMNIbus to achieve arbitrary code execution, information disclosure, file manipulation, or denial of service.

ibm tivoli netcool omnibus vulnerability code-execution dos
2r 3t