IBM
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any IBM product.
RSS Feeds for IBM security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in IBM products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by IBM Sorted by Most Security Vulnerabilities since 2018
Known Exploited IBM Vulnerabilities
The following IBM vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| IBM Langflow Code Injection Vulnerability |
Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments. CVE-2026-9198 |
August 4, 2026 |
| IBM Aspera Faspex Code Execution Vulnerability |
IBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a YAML deserialization flaw. CVE-2022-47986 Exploit Probability: 100.0% |
February 21, 2023 |
| IBM InfoSphere BigInsights Invalid Input Vulnerability |
Certain APIs within BigInsights can take invalid input that might allow attackers unauthorized access to read, write, modify, or delete data. CVE-2013-3993 Exploit Probability: 5.2% |
May 25, 2022 |
| IBM WebSphere Application Server and Server Hypervisor Edition Code Injection. |
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands CVE-2015-7450 Exploit Probability: 97.7% |
January 10, 2022 |
| IBM Data Risk Manager Arbritary File Download |
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to download arbitrary files from the system. IBM X-Force ID: 180535. CVE-2020-4430 Exploit Probability: 68.5% |
November 3, 2021 |
| IBM Data Risk Manager Authentication Bypass |
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system. IBM X-Force ID: 180532. CVE-2020-4427 Exploit Probability: 70.0% |
November 3, 2021 |
| IBM Data Risk Manager Command Injection |
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM X-Force ID: 180533. CVE-2020-4428 Exploit Probability: 61.7% |
November 3, 2021 |
| IBM Planning Analytics configuration overwrite vulnerability |
IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting. IBM X-Force ID: 172094. CVE-2019-4716 Exploit Probability: 86.4% |
November 3, 2021 |
Of the known exploited vulnerabilities above, 6 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings.
By the Year
In 2026 there have been 818 vulnerabilities in IBM with an average score of 7.0 out of ten. Last year, in 2025 IBM had 563 security vulnerabilities published. That is, 255 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.71.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 818 | 6.97 |
| 2025 | 563 | 6.26 |
| 2024 | 503 | 6.44 |
| 2023 | 357 | 6.80 |
| 2022 | 327 | 6.36 |
| 2021 | 443 | 6.10 |
| 2020 | 353 | 6.19 |
| 2019 | 454 | 6.14 |
| 2018 | 451 | 6.24 |
It may take a day or so for new IBM vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent IBM Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-19783 | Aug 20, 2026 |
IBM AIX/VIOS LLBO: Local Attacker OOB Write via Faulty FS ImageIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause kernel memory corruption due to insufficient validation. A crafted filesystem image can trigger an out-of-bounds kernel-stack write during directory reads, causing a system crash or potentially enabling privilege escalation. |
|
| CVE-2026-19449 | Aug 20, 2026 |
IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 cmdnim Lcl RCE to RootIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a vulnerability in cmdnim that may allow an unprivileged local user to executes the payload as root. |
|
| CVE-2026-19448 | Aug 20, 2026 |
IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 ESP Handler stack corruptionIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 A stack memory corruption vulnerability exists in the AIX IPsec ESP decapsulation handler. Successful exploitation may corrupt kernel stack state and cause a system crash, resulting in denial of service. |
|
| CVE-2026-19446 | Aug 20, 2026 |
IBM AIX 7.x Remote UDP DoS via crafted packetIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 allows a remote unauthenticated attacker can send a crafted UDP packet to a reachable RPC service, resulting in complete system unavailability and requiring an LPAR restart. |
|
| CVE-2026-19442 | Aug 20, 2026 |
IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 vSCSI Pointer Validation FlawIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtual SCSI (vSCSI) initiator driver. Successful exploitation may result in denial of service, privilege escalation, or full compromise of the client LPAR kernel. |
|
| CVE-2026-19437 | Aug 20, 2026 |
IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 Remote Code Exec via Buffer OverflowIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow. |
|
| CVE-2026-18835 | Aug 20, 2026 |
IBM AIX 7.2/7.3 & PowerVM VIOS 4.1: Remote Auth Cmd Exec via command injectionIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. |
|
| CVE-2026-18840 | Aug 20, 2026 |
IBM AIX 7.2/7.3 PowerVM VIOS 4.1: Local Code Exec via Pointer ValidationIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to improper validation of an attacker-controlled pointer. |
|
| CVE-2026-18842 | Aug 20, 2026 |
IBM AIX 7+ OOB Write Enables Escalated Privileges (CVE-2026-18842)IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to an out-of-bounds write. |
|
| CVE-2026-18832 | Aug 20, 2026 |
IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 Remote Heap Overflow RCEIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap-based buffer overflow. |
|
| CVE-2026-18828 | Aug 20, 2026 |
IBM AIX 7.2-7.3 / PowerVM VIOS 4.1 DoS via stack overflowIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a stack-based buffer overflow. |
|
| CVE-2026-18824 | Aug 20, 2026 |
IBM AIX 7.2-7.3 & PowerVM VIOS 4.1: RCE via OS Command InjectionIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. |
|
| CVE-2026-18822 | Aug 20, 2026 |
IBM AIX 7.2/7.3 & VIOS 4.1 DoS via uncontrolled dir record parsingIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to uncontrolled resource consumption when parsing directory records. |
|
| CVE-2026-18716 | Aug 20, 2026 |
IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 OOB Read Enables Remote Info DisclosureIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to obtain sensitive information or cause a denial of service due to an out-of-bounds read. |
|
| CVE-2026-18670 | Aug 20, 2026 |
IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 Integer Underflow DoSIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service and potentially disclose sensitive information due to an integer underflow. |
|
| CVE-2026-17436 | Aug 20, 2026 |
IBM AIX 7.2/7.3 & PowerVM VIOS 4.1: Remote RCE via Heap Buffer OverflowIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap-based buffer overflow. |
|
| CVE-2026-17425 | Aug 20, 2026 |
IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 Stack Buffer Overflow Leading to DoSIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a stack buffer overflow. |
|
| CVE-2026-17424 | Aug 20, 2026 |
IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 Remote Pathname BypassIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to bypass security restrictions due to improper limitation of a pathname to a restricted directory. |
|
| CVE-2026-17423 | Aug 20, 2026 |
IBM AIX/PowerVM VIOS 7.2/7.3/4.1 OOB Read Info Leak & DoSIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information and cause a denial of service due to an out-of-bounds read. |
|
| CVE-2026-17422 | Aug 20, 2026 |
Buffer Overflow Exploit in AIX 7.2/7.3 & PowerVM VIOS 4.1IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a buffer overflow. |
|
| CVE-2026-17195 | Aug 20, 2026 |
IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 Local DoS via OOB WriteIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to an out-of-bounds write. |
|
| CVE-2026-17171 | Aug 20, 2026 |
IBM AIX 7.2/7.3 & PowerVM 4.1 Local File Overwrite via SymlinkIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite arbitrary files due to improper resolution of symbolic links. |
|
| CVE-2026-17170 | Aug 20, 2026 |
DDoS via Allocation Size Validation in IBM AIX 7.27.3 & PowerVM VIOS 4.1IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to improper validation of an allocation size. |
|
| CVE-2026-17168 | Aug 20, 2026 |
IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 Stack Buffer Overflow CVE-2026-17168IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary code due to a stack-based buffer overflow. |
|
| CVE-2026-17165 | Aug 20, 2026 |
IBM AIX 7.2/7.3 & PowerVM VIOS 4.1: NULLptr DDoS via DSIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a NULL pointer dereference. |
|
| CVE-2026-17163 | Aug 20, 2026 |
IBM AIX 7.2/7.3 & VIOS 4.1 DoS via array size overvalidationIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to improper validation of an array size field. |
|
| CVE-2026-17160 | Aug 20, 2026 |
IBM AIX 7.x Remote Code Exec: Integer Overflow in Size ComputeIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an integer overflow during size computation. |
|
| CVE-2026-17159 | Aug 20, 2026 |
IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 Integer Overflow DoSIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an integer overflow. |
|
| CVE-2026-17157 | Aug 20, 2026 |
IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 stack buffer overflow RCEIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow. |
|
| CVE-2026-17152 | Aug 20, 2026 |
IBM AIX/PowerVM VIOS 7.2-7.3 & 4.1 Buffer Overflow RCEIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow. |
|
| CVE-2026-17145 | Aug 20, 2026 |
IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 Remote Code Exec via Privilege MismanageIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper privilege management. |
|
| CVE-2026-17142 | Aug 20, 2026 |
IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 Remote Command Execution via Improper AuthIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper authentication. |
|
| CVE-2026-17141 | Aug 20, 2026 |
IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 Remote Buffer OverflowIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow. |
|
| CVE-2026-17138 | Aug 20, 2026 |
IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 RCE via Stack Buffer OverflowIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow. |
|
| CVE-2026-17136 | Aug 20, 2026 |
Remote Code Exec: Format String in IBM AIX 7.2/7.3 & PowerVM VIOSIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a format string vulnerability. |
|
| CVE-2026-17124 | Aug 20, 2026 |
IBM AIX 7.2-7.3 / PowerVM VIOS 4.1 Local Code Exec via OOB ReadIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to an out-of-bounds read. |
|
| CVE-2026-17122 | Aug 20, 2026 |
IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 RCE via Stack Buffer OverflowIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow. |
|
| CVE-2026-17121 | Aug 20, 2026 |
IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 Recursion DoSIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to uncontrolled recursion. |
|
| CVE-2026-17120 | Aug 20, 2026 |
IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 Remote DoS via Buffer OverflowIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a buffer overflow. |
|
| CVE-2026-17118 | Aug 20, 2026 |
IBM AIX 7.x & PowerVM VIOS 4.1: UAF RCEIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a use-after-free vulnerability. |
|
| CVE-2026-17060 | Aug 20, 2026 |
IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 Kernel Heap Over-Read Remote Info Leak & DoSIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information and cause a denial of service due to a kernel heap over-read. |
|
| CVE-2026-17040 | Aug 20, 2026 |
IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 Buffer Overflow RE Code ExecIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow. |
|
| CVE-2026-17024 | Aug 20, 2026 |
IBM AIX 7.2-7.3 & PowerVM VIOS 4.1 RCE via Cert ValidationIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper certificate validation. |
|
| CVE-2026-17009 | Aug 20, 2026 |
Local DoS via NULL Pointer Deref in IBM AIX 7.2-7.3 & PowerVM VIOS 4.1IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to a NULL pointer dereference. |
|
| CVE-2026-17007 | Aug 20, 2026 |
IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 OOB Read for Local AttackerIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive information or cause a denial of service due to an out-of-bounds read. |
|
| CVE-2026-17006 | Aug 20, 2026 |
Heap Overflow in IBM AIX 7.2-7.3 & PowerVM VIOS 4.1: Remote Code ExecIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap buffer overflow. |
|
| CVE-2026-17003 | Aug 20, 2026 |
IBM AIX 7.2-7.3 & PowerVM VIOS 4.1 OOB Write Remote RCEIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to compromise the confidentiality and integrity of the system due to an out-of-bounds write. |
|
| CVE-2026-17000 | Aug 20, 2026 |
IBM AIX 7.2/7.3 & PowerVM VIOS 4.1: Remote RCE via Invalid AuthIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper authentication. |
|
| CVE-2026-16997 | Aug 20, 2026 |
IBM AIX 7.2/7.3 & PowerVM VIOS 4.1 LPE via Improper Privilege MgmtIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary commands due to improper privilege management. |
|
| CVE-2026-16996 | Aug 20, 2026 |
IBM AIX 7.2/7.3 & PowerVM VIOS 4.1: Local Exec via Integer UnderflowIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to an integer underflow. |
|