IBM
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any IBM product.
RSS Feeds for IBM security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in IBM products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by IBM Sorted by Most Security Vulnerabilities since 2018
Known Exploited IBM Vulnerabilities
The following IBM vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| IBM Langflow Code Injection Vulnerability |
Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments. CVE-2026-9198 |
August 4, 2026 |
| IBM Aspera Faspex Code Execution Vulnerability |
IBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a YAML deserialization flaw. CVE-2022-47986 Exploit Probability: 100.0% |
February 21, 2023 |
| IBM InfoSphere BigInsights Invalid Input Vulnerability |
Certain APIs within BigInsights can take invalid input that might allow attackers unauthorized access to read, write, modify, or delete data. CVE-2013-3993 Exploit Probability: 5.2% |
May 25, 2022 |
| IBM WebSphere Application Server and Server Hypervisor Edition Code Injection. |
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands CVE-2015-7450 Exploit Probability: 97.7% |
January 10, 2022 |
| IBM Data Risk Manager Arbritary File Download |
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to download arbitrary files from the system. IBM X-Force ID: 180535. CVE-2020-4430 Exploit Probability: 68.5% |
November 3, 2021 |
| IBM Data Risk Manager Authentication Bypass |
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system. IBM X-Force ID: 180532. CVE-2020-4427 Exploit Probability: 70.0% |
November 3, 2021 |
| IBM Data Risk Manager Command Injection |
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM X-Force ID: 180533. CVE-2020-4428 Exploit Probability: 61.7% |
November 3, 2021 |
| IBM Planning Analytics configuration overwrite vulnerability |
IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting. IBM X-Force ID: 172094. CVE-2019-4716 Exploit Probability: 86.4% |
November 3, 2021 |
Of the known exploited vulnerabilities above, 6 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings.
By the Year
In 2026 there have been 955 vulnerabilities in IBM with an average score of 7.0 out of ten. Last year, in 2025 IBM had 563 security vulnerabilities published. That is, 392 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.73.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 955 | 6.98 |
| 2025 | 563 | 6.26 |
| 2024 | 503 | 6.44 |
| 2023 | 357 | 6.80 |
| 2022 | 327 | 6.36 |
| 2021 | 443 | 6.10 |
| 2020 | 353 | 6.19 |
| 2019 | 454 | 6.14 |
| 2018 | 451 | 6.24 |
It may take a day or so for new IBM vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent IBM Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-2310 | Sep 10, 2026 |
IBM webMethods Integration Server 11.1 XXE Vulnerability in XML ProcessingIBM webMethods Integration Server 11.1 IBM webMethods Integration is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. |
|
| CVE-2026-19646 | Sep 10, 2026 |
IBM Common Licensing Agent 9.0 Host Header Validation Allows Remote RedirectionIBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 could allow a remote attacker to redirect users to an arbitrary domain due to improper validation of the HTTP Host header. |
|
| CVE-2026-75624 | Sep 10, 2026 |
IBM App Connect Enterprise 13.x Auth Bypass via Incorrect AuthorizationIBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.27 could allow a remote authenticated attacker to bypass security restrictions due to incorrect authorization. |
|
| CVE-2026-75777 | Sep 10, 2026 |
IBM Aspera Enterprise WebApps 1.0.0-1.0.5: Local Cntr Escape via SyscallsIBM Aspera Enterprise WebApps 1.0.0 through 1.0.5 could allow a local attacker to escape container protections due to unrestricted system calls being permitted within the container. |
|
| CVE-2026-76059 | Sep 10, 2026 |
IBM Langflow OSS 1.0.0-1.11.5 Arbitrary OS Exec via Custom Comp InjectionIBM Langflow OSS 1.0.0 through 1.11.5 An attacker who could submit custom component source code could bypass the static security scanner by crafting an annotated class-body assignment that resolved to a dangerous callable through alias tracking; the resolved value was never checked against the dangerous callable blocklist due to the logic error. If the crafted component reached the runtime execution path, the attacker could cause arbitrary operating system commands to execute on the server in-process, with the privileges of the running service. |
|
| CVE-2026-78569 | Sep 10, 2026 |
IBM Langflow OSS 1.0.0-1.11.5 Auth RCE via DenylistIBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to execute arbitrary code due to an incomplete denylist in the security scanner. |
|
| CVE-2026-78571 | Sep 10, 2026 |
IBM Langflow OSS 1.0.0-1.11.5 RCE via unguarded eval()IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an unguarded eval() call on attacker-controlled input. |
|
| CVE-2026-78573 | Sep 10, 2026 |
IBM ContextForge MCP Gateway 1.0.0-1.0.7 Default Credentials Remote Admin AccessIBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a remote attacker to gain administrative access due to the use of default credentials. |
|
| CVE-2026-78575 | Sep 10, 2026 |
IBM Langflow OSS 1.0.0-1.11.5 Cmd Injection via MCP stdio serverIBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of command-line arguments in the MCP stdio server configuration. |
|
| CVE-2026-79723 | Sep 10, 2026 |
IBM Langflow OSS 1.0.01.11.5 RAA via improper API endpoint validationIBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of user-controlled API endpoints. |
|
| CVE-2026-79724 | Sep 10, 2026 |
IBM Langflow OSS 1.0.0-1.11.5 RCE via OS Command InjectionIBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command. |
|
| CVE-2026-79725 | Sep 10, 2026 |
IBM Langflow OSS 1.0.0-1.11.5 Auth File Read via Improper Access ControlIBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to read arbitrary files due to improper access control. |
|
| CVE-2026-79742 | Sep 10, 2026 |
Langflow OSS 1.0.01.11.5 RCE via incomplete env var blocklistIBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an incomplete environment variable blocklist. |
|
| CVE-2026-80378 | Sep 10, 2026 |
IBM DataStage on Cloud Pak for Data 5.4.0.0 Auth Bypass Causing DOSIBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to improper authorization. |
|
| CVE-2026-80380 | Sep 10, 2026 |
IBM DataStage on Cloud Pak for Data 5.4.0.0: CSRF Enables Unauthorized ActionsIBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote attacker to perform unauthorized actions due to cross-site request forgery. |
|
| CVE-2026-80434 | Sep 10, 2026 |
IBM DataStage Cloud Pak 5.4.0.0 IDOR Causing Runtime Cache Manipulation & DoSIBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to manipulate runtime caches and cause a denial of service due to an insecure direct object reference. |
|
| CVE-2026-80424 | Sep 10, 2026 |
IBM DataStage CloudPak Path Traversal 5.4.0.0 Enables Auth Remote File WriteIBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to create arbitrary files due to path traversal during archive extraction. |
|
| CVE-2026-80436 | Sep 10, 2026 |
IBM DataStage Cloud Pak 5.4: Authenticated DOS via RabbitMQ DeletionIBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service by deleting arbitrary RabbitMQ queues or exchanges due to improper authorization. |
|
| CVE-2026-81204 | Sep 10, 2026 |
IBM Langflow OSS <1.12 - RCE via Graph Construction Code InjectionIBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code due to code injection during graph construction. |
|
| CVE-2026-81207 | Sep 10, 2026 |
IBM DataStage CP4D 5.4.0.0 ds-canvas: Auth. tenant controls outbound fetch URLsIBM DataStage on Cloud Pak for Data 5.4.0.0 allows any authenticated tenant with no project membership or role fully controls scheme/host/port/path of an outbound fetch originating from a shared-infrastructure pod, and the WSDL body is reflected verbatim to the caller. The ds-canvas pod sits on the OpenShift overlay with reach to co-tenant services, in-cluster CP4D APIs, and link-local addresses. Scope is Changed, confidentiality High (response-reflecting), integrity Low (GET-only side-effects). |
|
| CVE-2026-81210 | Sep 10, 2026 |
IBM DataStage Cloud Pak 5.4 IDOR & Path Traversal via Log FilesIBM DataStage on Cloud Pak for Data 5.4.0.0 concatenates three caller-supplied strings into a String.format path on the shared /ds-storage RWX PVC and returns the file with no project ACL pure IDOR plus traversal. Read is constrained to files named job.log/error.log, but DataStage job logs routinely carry connection strings, {dsnextenc} ciphertexts (decryptable via d2-f023), and customer-data row samples. This is the operator's tenant-to-tenant PVC-leakage threat verbatim; MEDIUMHIGH via threat match. |
|
| CVE-2026-81211 | Sep 10, 2026 |
IBM Langflow OSS 1.0.0-1.11.5 Remote Code Exec via Custom Component Auth BypassIBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary Python code due to improper authorization of custom components in stored flows. |
|
| CVE-2026-81941 | Sep 10, 2026 |
IBM Langflow OSS 1.0.0-1.11.5 Authenticated OS Command Execution via MCP ToolsIBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating system commands on the server at the privilege level of the application process by constructing a flow with an MCP Tools component configured to use a local stdio subprocess transport. This bypasses both the LANGFLOW_CUSTOM_COMPONENT_ADMIN_ONLY and LANGFLOW_BLOCK_CODE_INTERPRETER_COMPONENTS server-side controls intended to prevent exactly this class of access. Successful exploitation could lead to arbitrary command execution, sensitive data exposure (including credentials from the process environment), file system modification, and lateral movement to services reachable from the server. |
|
| CVE-2026-81213 | Sep 10, 2026 |
IBM Langflow OSS 1.0.01.11.5 URL Validation Remote Info DisclosureIBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to obtain sensitive information from internal network resources due to improper validation of user-supplied URLs. |
|
| CVE-2026-81265 | Sep 10, 2026 |
IBM Langflow OSS 1.0.0-1.11.5: Vulnerable Component Exposes Remote Code ExecIBM Langflow OSS 1.0.0 through 1.11.5. |
|
| CVE-2026-81268 | Sep 10, 2026 |
IBM Langflow OSS 1.0.0-1.11.5 API Key Session Expiration BypassIBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute flows and obtain sensitive information due to insufficient session expiration of API keys after user deactivation. |
|
| CVE-2026-81540 | Sep 10, 2026 |
IBM DataStage 5.4.0.0 Path Traversal Enables Auth Tenant Ruleset OverwriteIBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to overwrite ruleset files belonging to other tenants due to a path traversal vulnerability. |
|
| CVE-2026-81550 | Sep 10, 2026 |
IBM DataStage 5.4.0.0 RCE via improper OS command escapingIBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command. |
|
| CVE-2026-81551 | Sep 10, 2026 |
IBM DataStage Cloud Pak 5.4.0 Path Traversal Enables Remote File WriteIBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to arbitrarily write to or delete files on shared storage due to a path traversal vulnerability. |
|
| CVE-2026-81554 | Sep 10, 2026 |
IBM DataStage on Cloud Pak for Data 5.4.0.0 Path Traversal Remote Auth AttackIBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability. |
|
| CVE-2026-81940 | Sep 10, 2026 |
IBM Langflow OSS <1.12: RCE via unsanitized flow display namesIBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special characters in flow display names. |
|
| CVE-2026-82092 | Sep 10, 2026 |
IBM DataStage 5.4.0.0 APT: Absolute-Path Traversal Remote Auth Get Sensitive InfoIBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability. |
|
| CVE-2026-82095 | Sep 10, 2026 |
IBM DataStage Cloud Pak 5.4.0.0 OS Command Injection via Improper EscapingIBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command. |
|
| CVE-2026-82097 | Sep 10, 2026 |
IBM DataStage on Cloud Pak for Data 5.4.0.0 SSRF RCEIBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to a Server-Side Request Forgery (SSRF) vulnerability. |
|
| CVE-2026-82098 | Sep 10, 2026 |
Remote Authenticated Command Injection in IBM DataStage Cloud Pak 5.4.0.0IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. |
|
| CVE-2026-82099 | Sep 10, 2026 |
IBM DataStage on Cloud Pak 5.4.0.0: Authenticated RCE via OS Command InjectionIBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command. |
|
| CVE-2026-82100 | Sep 10, 2026 |
IBM DataStage 5.4.0.0 Path Traversal DoS (Auth)IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability. |
|
| CVE-2026-82107 | Sep 10, 2026 |
IBM DS Cloud Pak 5.4 Improper Auth Bypass Remote Data ExfilIBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication. |
|
| CVE-2026-84889 | Sep 10, 2026 |
IBM Langflow OSS 1.0.0-1.10.3 RCE via Unrestricted PathnameIBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory. |
|
| CVE-2026-86087 | Sep 10, 2026 |
IBM Db2 11.5.0-11.5.9/12.1.0-12.1.5 Auth File Write via Crafted ReqIBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an authenticated user to send a specially crafted request to write arbitrary files on the system. |
|
| CVE-2026-86093 | Sep 10, 2026 |
IBM Db2 11.5/12.1 Stack Buffer Overflow via DRDA Client (CVE-2026-86093)IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer overflow that improperly copies user-controlled data into a fixed-size stack buffer without bounds checking. |
|
| CVE-2026-87958 | Sep 10, 2026 |
IBM Db2 11.5.0-11.5.9/12.1.0-12.1.5 DoS via Privileged User Disabling FunctionalityIBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions. |
|
| CVE-2026-85025 | Sep 10, 2026 |
IBM Langflow OSS 1.0.0-1.11.5 Unauth Remote Code Exec via Public MCP EndpointsIBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due to improper enforcement of public-flow security restrictions and session isolation controls. |
|
| CVE-2026-9667 | Sep 10, 2026 |
IBM WebSphere AS SSRF in 9.0/8.5: remote unauthenticated attackIBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) that could allow a remote, unauthenticated attacker to cause the server to send outbound requests to arbitrary endpoints. |
|
| CVE-2026-9176 | Sep 10, 2026 |
IBM WebSphere App Server 8.5/9.0 Auth Bypass Prior to 9.1IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a security bypass due to improper authentication controls. A local attacker could exploit this vulnerability to escalate privileges and gain unauthorized access to protected resources. |
|
| CVE-2026-9225 | Sep 10, 2026 |
IBM Langflow OSS 1.0.0-1.11.5 AuthC Bypass in File/Read File ComponentIBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an authenticated attacker to access sensitive files belonging to other users due to improper access control in the File/Read File component. When executing flows through the /api/v1/run/advanced/{flow_id} endpoint, the application allows component inputs to reference storage paths using arbitrary user or flow identifiers without verifying ownership. An attacker with lowprivileged authenticated access can supply a crafted file path pointing to another users storage namespace, causing the backend to read and return the contents of files uploaded by other users. This vulnerability bypasses intended authorization checks enforced by the file management API and may result in unauthorized disclosure of sensitive user data. |
|
| CVE-2026-9327 | Sep 10, 2026 |
IBM WebSphere AppServer 8.5-9.0: Low-Priv Auth Admin Mod Config for Info Leak/DoSIBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege administrative role to modify security configuration. This could result in information disclosure or denial of service. |
|
| CVE-2026-9336 | Sep 10, 2026 |
IBM WebSphere App Server 8.5-9.0 DoS via Admin HTTP EndpointIBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted HTTP request to an administrative endpoint. A remote attacker could exploit this vulnerability to cause the server to exhaust filesystem space. |
|
| CVE-2026-9338 | Sep 10, 2026 |
IBM WebSphere App Server 8.5-9.0 DoS via crafted requestIBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to trigger excessive resource consumption, potentially leading to reduced availability of the affected service. |
|
| CVE-2026-19625 | Sep 08, 2026 |
Quarkus OIDC Introspection Cache Enables CrossTenant Token UseWhen a Quarkus application has multiple endpoints secured by individual OIDC provider tenants, such as "/oidc-provider1" that is secured by the OIDC Provider 1 and "/oidc-provider2" that is secured by the OIDC Provider 2, and an optional token introspection cache is also enabled, then a valid token issued by the OIDC Provider 1 that can be used to access "/oidc-provider1" can also be used to access "/oidc-provider2" that is secured by another OIDC Provider 2. |
|