IBM
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any IBM product.
RSS Feeds for IBM security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in IBM products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by IBM Sorted by Most Security Vulnerabilities since 2018
Known Exploited IBM Vulnerabilities
The following IBM vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| IBM Langflow Code Injection Vulnerability |
Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments. CVE-2026-9198 |
August 4, 2026 |
| IBM Aspera Faspex Code Execution Vulnerability |
IBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a YAML deserialization flaw. CVE-2022-47986 Exploit Probability: 100.0% |
February 21, 2023 |
| IBM InfoSphere BigInsights Invalid Input Vulnerability |
Certain APIs within BigInsights can take invalid input that might allow attackers unauthorized access to read, write, modify, or delete data. CVE-2013-3993 Exploit Probability: 5.2% |
May 25, 2022 |
| IBM WebSphere Application Server and Server Hypervisor Edition Code Injection. |
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands CVE-2015-7450 Exploit Probability: 97.7% |
January 10, 2022 |
| IBM Data Risk Manager Arbritary File Download |
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to download arbitrary files from the system. IBM X-Force ID: 180535. CVE-2020-4430 Exploit Probability: 68.5% |
November 3, 2021 |
| IBM Data Risk Manager Authentication Bypass |
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system. IBM X-Force ID: 180532. CVE-2020-4427 Exploit Probability: 70.0% |
November 3, 2021 |
| IBM Data Risk Manager Command Injection |
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM X-Force ID: 180533. CVE-2020-4428 Exploit Probability: 61.7% |
November 3, 2021 |
| IBM Planning Analytics configuration overwrite vulnerability |
IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting. IBM X-Force ID: 172094. CVE-2019-4716 Exploit Probability: 86.4% |
November 3, 2021 |
Of the known exploited vulnerabilities above, 6 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings.
By the Year
In 2026 there have been 904 vulnerabilities in IBM with an average score of 6.9 out of ten. Last year, in 2025 IBM had 563 security vulnerabilities published. That is, 341 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.66.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 904 | 6.92 |
| 2025 | 563 | 6.26 |
| 2024 | 503 | 6.44 |
| 2023 | 357 | 6.80 |
| 2022 | 327 | 6.36 |
| 2021 | 443 | 6.10 |
| 2020 | 353 | 6.19 |
| 2019 | 454 | 6.14 |
| 2018 | 451 | 6.24 |
It may take a day or so for new IBM vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent IBM Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-13297 | Sep 04, 2026 |
IBM Verify Identity Access: Adv Access Control Info DisclosureIBM Verify Identity Access Advanced Access Control may be vulnerable to an information disclosure attack. |
And others... |
| CVE-2026-14350 | Sep 04, 2026 |
IBM CloudPak Data 11.3.x log injection via improper neutralizationIBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files. |
|
| CVE-2026-14470 | Sep 04, 2026 |
IBM Langflow OSS 1.0.0-1.10.2 Directory Traversal via URL (dotdot)IBM Langflow OSS 1.0.0 through 1.10.2 could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. |
|
| CVE-2026-16180 | Sep 04, 2026 |
IBM App Connect Enterprise 13.x DoS via XML Entity Validation (CVE-2026-16180)IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 Toolkit could allow an authenticated user to cause a denial-of-service condition due to improper validation of XML entities. |
|
| CVE-2026-16660 | Sep 04, 2026 |
IBM Db2 Mirror for i OOB Read Leading to DoS 7.4-7.6IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds read. |
|
| CVE-2026-16689 | Sep 04, 2026 |
IBM App Connect Enterprise 12/13.0.x: Local Credential Exposure via LoggingIBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to improper logging of credentials. |
|
| CVE-2026-16693 | Sep 04, 2026 |
IBM i 7.3-7.6 Hardcoded Crypto Constants Remote Disclosure of Sensitive DataIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to the use of hardcoded cryptographic constants to obfuscate encryption keys. |
|
| CVE-2026-16826 | Sep 04, 2026 |
IBM i 7.6/7.5/7.4/7.3 Local Command Injection via Improper SanitizationIBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. |
|
| CVE-2026-16892 | Sep 04, 2026 |
IBM i 7.67.3 Auth Bypass via ServiceName MatchingIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper authentication during service-name matching. |
|
| CVE-2026-16941 | Sep 04, 2026 |
IBM i 7.6 Remote Auth System Msg Mod via Improper AuthIBM i 7.6, 7.5, and 7.4 could allow a remote authenticated attacker to modify certain system messages due to improper authorization. |
|
| CVE-2026-17057 | Sep 04, 2026 |
IBM i 7.6/7.5/7.4/7.3 Remote Auth Bypass Enables DoS & Data Integrity ImpactIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and affect data integrity due to missing authentication for critical functions. |
|
| CVE-2026-17207 | Sep 04, 2026 |
IBM i (7.6-7.3) Buffer Overflow Enables DoS & Integrity CompromiseIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and compromise integrity due to a buffer overflow. |
|
| CVE-2026-17255 | Sep 04, 2026 |
IBM i 7.6-7.3 Remote DoS via ICMPv6 Prefix Length ValidationIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of the prefix length in ICMPv6 Router Advertisements. |
|
| CVE-2026-17259 | Sep 04, 2026 |
IBM i 7.6 Stack Buffer Overflow Remote DoSIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a stack-based buffer overflow. |
|
| CVE-2026-17270 | Sep 04, 2026 |
IBM i 7.3-7.6 Stack Buffer Overflow Denial of ServiceIBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to a stack-based buffer overflow. |
|
| CVE-2026-17273 | Sep 04, 2026 |
IBM i 7.6-7.3 NULL Deref DOS Remote AuthIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a NULL pointer dereference. |
|
| CVE-2026-17274 | Sep 04, 2026 |
IBM i 7.6/7.5/7.4/7.3 Security Bypass via Predictable Server SeedsIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to predictable server seeds. |
|
| CVE-2026-17440 | Sep 04, 2026 |
IBM App Connect 12/13 & Integration Bus z/OS: Recursion DoS (13.0.8.1)IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to cause a denial of service due to uncontrolled recursion. |
|
| CVE-2026-17442 | Sep 04, 2026 |
IBM App Connect Enterprise 13.x Trace Log Credential Leakage (Cleartext)IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to credentials being written to trace logs in cleartext. |
|
| CVE-2026-17443 | Sep 04, 2026 |
IBM App Connect Enterprise XXE (v13.x, v12.x, z/OS 10.1.x)IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection flaw. |
|
| CVE-2026-17444 | Sep 04, 2026 |
IBM App Connect Enterprise XXE Info Leak 13.0.1.0-13.0.8.1IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection. |
|
| CVE-2026-17469 | Sep 04, 2026 |
IBM i 7.6/7.5/7.4/7.3 LPD Queue Name Parser Off-by-One Write Causes DoSIBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to an off-by-one write in the LPD queue name parser. |
|
| CVE-2026-17470 | Sep 04, 2026 |
IBM i OS 7.6/7.5/7.4/7.3 Buffer Overflow DoSIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a buffer overflow. |
|
| CVE-2026-17483 | Sep 04, 2026 |
IBM Db2 7.4-7.6: Improper Access Control Allows Deletion of FlightRec ArchivesIBM Db2 Mirror for i 7.4, 7.5, and 7.6 IBM i could allow a local attacker to delete historical flight-recorder archives due to improper access control in an SQL procedure. |
|
| CVE-2026-17499 | Sep 04, 2026 |
IBM i 7.6 Local Command Injection via Improper OS Command NeutralizationIBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. |
|
| CVE-2026-17627 | Sep 04, 2026 |
IBM Langflow OSS 1.01.10.2 Auth Bypass Enables Data Theft & Workflow InjectionIBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information and inject messages into workflow history due to improper authorization. |
|
| CVE-2026-17621 | Sep 04, 2026 |
IBM Langflow OSS 1.0.01.10.2 Directory Traversal via URLIBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to view arbitrary files on the system. |
|
| CVE-2026-17622 | Sep 04, 2026 |
IBM Langflow OSS <=1.10.2 Info Disclosure via Pathname Directory TraversalIBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory. |
|
| CVE-2026-17631 | Sep 04, 2026 |
IBM Langflow OSS 1.0.0-1.10.2 SSRF Remote Authenticated Info LeakIBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to a server-side request forgery (SSRF) vulnerability. |
|
| CVE-2026-18073 | Sep 04, 2026 |
IBM i 7.x CL Command Param Injection (CVE-2026-18073)IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to inject parameters into a CL command due to improper neutralization of special elements. |
|
| CVE-2026-18078 | Sep 04, 2026 |
IBM i 7.x DOS via Remote Authenticated Integer OverflowIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to an integer overflow. |
|
| CVE-2026-18076 | Sep 04, 2026 |
IBM i 7.6-7.3 Memory Leak Remote Authenticated DoSIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a memory leak. |
|
| CVE-2026-18175 | Sep 04, 2026 |
IBM i 7.6/7.5/7.4/7.3 Impr Auth in DDM Target Dis Enables Remote DB Tx ManipIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate database transactions due to improper authorization in the DDM target dispatcher. |
|
| CVE-2026-18221 | Sep 04, 2026 |
IBM i 7.6/7.5/7.4/7.3 auth param validation flawIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improper validation of client-supplied authentication parameters. |
|
| CVE-2026-18341 | Sep 04, 2026 |
IBM i 7.x Memory Corruption via Integer Underflow (Remote Auth.)IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to corrupt memory due to an integer underflow. |
|
| CVE-2026-18486 | Sep 04, 2026 |
CVE-2026-18486: IBM ContextForge MCP Gateway <=1.0.7 jq Filter Credential TheftIBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive credentials and escalate privileges due to improper validation of jq filters. |
|
| CVE-2026-18489 | Sep 04, 2026 |
IBMCF MCP Translate <=1.0.8 Remote Info DisclosureIBM ContextForge MCP Gateway - Translate utility <= 1.0.8 MCP Context Forge could allow a remote attacker to obtain sensitive information from other sessions due to exposure of data elements to the wrong session. |
|
| CVE-2026-18567 | Sep 04, 2026 |
IBM Db2 Mirror 7.47.6 Local Info Disclosure via Race on Writable SocketIBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a local attacker to obtain information due to a race condition involving a predictable Unix domain socket path in a world-writable directory. |
|
| CVE-2026-18658 | Sep 04, 2026 |
IBM OOM 9.6.0 SQLi allows RCE via web shellIBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execute arbitrary SQL statements and leverage database functionality to write a web shell to the application web root, resulting in remote code execution. |
|
| CVE-2026-18858 | Sep 04, 2026 |
IBM i 7.6/7.5 SSH Local Auth Privileged File DisclosureIBM i 7.6, and 7.5 could allow a local authenticated attacker to obtain information from a privileged file when using SSH. |
|
| CVE-2026-18887 | Sep 04, 2026 |
IBM i 7.6-7.3 PASE Authenticated Process Info DisclosureIBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to obtain sensitive information in PASE. An attacker could exploit this vulnerability to access information about process they shouldn't be permitted to access. |
|
| CVE-2026-19298 | Sep 04, 2026 |
Remote Auth. AUC Exec via Auth Bypass in IBM Langflow v1.01.11.2IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute arbitrary code due to an authorization bypass in the flow build process. |
|
| CVE-2026-19301 | Sep 04, 2026 |
ServerSide Request Forgery in IBM Langflow OSS <1.11.2IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery. |
|
| CVE-2026-19303 | Sep 04, 2026 |
IBM Langflow OSS <1.11.2: Remote Authenticated File Deletion via Path TraversalIBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to delete arbitrary local files or directories due to improper limitation of a pathname to a restricted directory. |
|
| CVE-2026-18905 | Sep 04, 2026 |
IBM ContextForge MCP Gateway <=1.0.6 DNS Rebinding Remote Auth Info DisclosureIBM ContextForge MCP Gateway (`mcp-contextforge-gateway`) <= v1.0.6 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive information due to a DNS rebinding vulnerability during tool invocation. |
|
| CVE-2026-19274 | Sep 04, 2026 |
IBM Instana Agent Operator RBAC hijack < 1.0.324IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated Kubernetes tenant to hijack or permanently destroy another tenant's cluster-level RBAC permissions, caused by cluster-scoped RBAC objects being keyed solely by the bare CR name with no namespace disambiguation, allowing a same-named `InstanaAgent` CR in an attacker-controlled namespace to silently overwrite the shared `ClusterRoleBinding` or delete it outright and revoke the victim agent's cluster monitoring access. |
|
| CVE-2026-19283 | Sep 04, 2026 |
IBM Instana Agent Operator 1.0.303-1.0.323 Remote Authenticated Data LeakIBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated remote attacker to obtain sensitive information, caused by missing destination namespace validation when copying etcd mTLS client credentials from the openshift-etcd system namespace into an attacker-controlled namespace. |
|
| CVE-2026-19300 | Sep 04, 2026 |
IBM Langflow OSS 1.0-1.11.2: Incomplete Credential Scrubbing Allows Info LeakIBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to incomplete scrubbing of sensitive credential fields. |
|
| CVE-2026-19299 | Sep 04, 2026 |
IBM Langflow OSS 1.0.0-1.11.2 Path Traversal CVE-2026-19299IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to path traversal. |
|
| CVE-2026-19302 | Sep 04, 2026 |
IBM Langflow OSS 1.0-1.11.2 Authenticated Remote Info Leak via SymlinkIBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links. |
|