IBM IBM

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any IBM product.

RSS Feeds for IBM security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in IBM products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by IBM Sorted by Most Security Vulnerabilities since 2018

IBM I426 vulnerabilities

IBM Aix269 vulnerabilities

IBM Db2152 vulnerabilities

IBM Powervm Vios144 vulnerabilities

IBM Sterling B2b Integrator143 vulnerabilities

IBM Rational Quality Manager132 vulnerabilities

IBM Langflow Oss111 vulnerabilities

IBM Cognos Analytics98 vulnerabilities

IBM Security Verify Access95 vulnerabilities

IBM Security Guardium84 vulnerabilities

IBM Maximo Asset Management78 vulnerabilities

IBM Api Connect77 vulnerabilities

IBM Vios74 vulnerabilities

IBM Mq67 vulnerabilities

IBM Rational Team Concert65 vulnerabilities

IBM Sterling File Gateway62 vulnerabilities

IBM Concert55 vulnerabilities

IBM Security Access Manager49 vulnerabilities

IBM Cloud Pak For Security48 vulnerabilities

IBM Cognos Controller48 vulnerabilities

IBM Aspera Faspex44 vulnerabilities

IBM Planning Analytics42 vulnerabilities

IBM Urbancode Deploy42 vulnerabilities

IBM Spectrum Scale42 vulnerabilities

IBM Mq Appliance41 vulnerabilities

IBM Robotic Process Automation40 vulnerabilities

IBM Maximo Application Suite34 vulnerabilities

IBM App Connect Enterprise33 vulnerabilities

IBM Business Process Manager33 vulnerabilities

IBM Planning Analytics Local32 vulnerabilities

IBM Cics Tx31 vulnerabilities

IBM Jazz Reporting Service29 vulnerabilities

IBM Qradar Siem29 vulnerabilities

IBM Power Systems Firmware28 vulnerabilities

IBM Verify Identity Access28 vulnerabilities

IBM Cloud Pak System28 vulnerabilities

IBM Spectrum Protect Plus27 vulnerabilities

IBM Content Navigator27 vulnerabilities

IBM Db2 Mirror For I26 vulnerabilities

IBM Concert Software23 vulnerabilities

IBM Qradar Suite23 vulnerabilities

IBM Security Identity Manager22 vulnerabilities

IBM Openpages With Watson22 vulnerabilities

IBM Spectrum Protect21 vulnerabilities

IBM Informix Dynamic Server21 vulnerabilities

IBM Controller21 vulnerabilities

IBM Bigfix Platform20 vulnerabilities

IBM Websphere Mq19 vulnerabilities

IBM Datacap19 vulnerabilities

IBM Sterling Secure Proxy19 vulnerabilities

IBM Powervm Hypervisor19 vulnerabilities

IBM Aspera Console18 vulnerabilities

IBM Security Secret Server18 vulnerabilities

IBM Security Verify Governance18 vulnerabilities

IBM Datacap Navigator18 vulnerabilities

IBM Websphere Portal18 vulnerabilities

IBM Security Qradar Edr17 vulnerabilities

IBM Aspera Shares16 vulnerabilities

IBM Security Directory Server16 vulnerabilities

IBM Applinx15 vulnerabilities

Known Exploited IBM Vulnerabilities

The following IBM vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.

Title Description Added
IBM Langflow Code Injection Vulnerability Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.
CVE-2026-9198
August 4, 2026
IBM Aspera Faspex Code Execution Vulnerability IBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a YAML deserialization flaw.
CVE-2022-47986 Exploit Probability: 100.0%
February 21, 2023
IBM InfoSphere BigInsights Invalid Input Vulnerability Certain APIs within BigInsights can take invalid input that might allow attackers unauthorized access to read, write, modify, or delete data.
CVE-2013-3993 Exploit Probability: 5.2%
May 25, 2022
IBM WebSphere Application Server and Server Hypervisor Edition Code Injection. Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands
CVE-2015-7450 Exploit Probability: 97.7%
January 10, 2022
IBM Data Risk Manager Arbritary File Download IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to download arbitrary files from the system. IBM X-Force ID: 180535.
CVE-2020-4430 Exploit Probability: 68.5%
November 3, 2021
IBM Data Risk Manager Authentication Bypass IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system. IBM X-Force ID: 180532.
CVE-2020-4427 Exploit Probability: 70.0%
November 3, 2021
IBM Data Risk Manager Command Injection IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM X-Force ID: 180533.
CVE-2020-4428 Exploit Probability: 61.7%
November 3, 2021
IBM Planning Analytics configuration overwrite vulnerability IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting. IBM X-Force ID: 172094.
CVE-2019-4716 Exploit Probability: 86.4%
November 3, 2021

Of the known exploited vulnerabilities above, 6 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings.

By the Year

In 2026 there have been 955 vulnerabilities in IBM with an average score of 7.0 out of ten. Last year, in 2025 IBM had 563 security vulnerabilities published. That is, 392 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.73.




Year Vulnerabilities Average Score
2026 955 6.98
2025 563 6.26
2024 503 6.44
2023 357 6.80
2022 327 6.36
2021 443 6.10
2020 353 6.19
2019 454 6.14
2018 451 6.24

It may take a day or so for new IBM vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent IBM Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-2310 Sep 10, 2026
IBM webMethods Integration Server 11.1 XXE Vulnerability in XML Processing IBM webMethods Integration Server 11.1 IBM webMethods Integration is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Webmethods Integration Server
CVE-2026-19646 Sep 10, 2026
IBM Common Licensing Agent 9.0 Host Header Validation Allows Remote Redirection IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 could allow a remote attacker to redirect users to an arbitrary domain due to improper validation of the HTTP Host header.
Common Licensing
CVE-2026-75624 Sep 10, 2026
IBM App Connect Enterprise 13.x Auth Bypass via Incorrect Authorization IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.27 could allow a remote authenticated attacker to bypass security restrictions due to incorrect authorization.
App Connect Enterprise
CVE-2026-75777 Sep 10, 2026
IBM Aspera Enterprise WebApps 1.0.0-1.0.5: Local Cntr Escape via Syscalls IBM Aspera Enterprise WebApps 1.0.0 through 1.0.5 could allow a local attacker to escape container protections due to unrestricted system calls being permitted within the container.
Aspera Enterprise Webapps
CVE-2026-76059 Sep 10, 2026
IBM Langflow OSS 1.0.0-1.11.5 Arbitrary OS Exec via Custom Comp Injection IBM Langflow OSS 1.0.0 through 1.11.5 An attacker who could submit custom component source code could bypass the static security scanner by crafting an annotated class-body assignment that resolved to a dangerous callable through alias tracking; the resolved value was never checked against the dangerous callable blocklist due to the logic error. If the crafted component reached the runtime execution path, the attacker could cause arbitrary operating system commands to execute on the server in-process, with the privileges of the running service.
Langflow Oss
CVE-2026-78569 Sep 10, 2026
IBM Langflow OSS 1.0.0-1.11.5 Auth RCE via Denylist IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to execute arbitrary code due to an incomplete denylist in the security scanner.
Langflow Oss
CVE-2026-78571 Sep 10, 2026
IBM Langflow OSS 1.0.0-1.11.5 RCE via unguarded eval() IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an unguarded eval() call on attacker-controlled input.
Langflow Oss
CVE-2026-78573 Sep 10, 2026
IBM ContextForge MCP Gateway 1.0.0-1.0.7 Default Credentials Remote Admin Access IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a remote attacker to gain administrative access due to the use of default credentials.
Contextforge Mcp Gateway
CVE-2026-78575 Sep 10, 2026
IBM Langflow OSS 1.0.0-1.11.5 Cmd Injection via MCP stdio server IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of command-line arguments in the MCP stdio server configuration.
Langflow Oss
CVE-2026-79723 Sep 10, 2026
IBM Langflow OSS 1.0.01.11.5 RAA via improper API endpoint validation IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of user-controlled API endpoints.
Langflow Oss
CVE-2026-79724 Sep 10, 2026
IBM Langflow OSS 1.0.0-1.11.5 RCE via OS Command Injection IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.
Langflow Oss
CVE-2026-79725 Sep 10, 2026
IBM Langflow OSS 1.0.0-1.11.5 Auth File Read via Improper Access Control IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to read arbitrary files due to improper access control.
Langflow Oss
CVE-2026-79742 Sep 10, 2026
Langflow OSS 1.0.01.11.5 RCE via incomplete env var blocklist IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an incomplete environment variable blocklist.
Langflow Oss
CVE-2026-80378 Sep 10, 2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 Auth Bypass Causing DOS IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to improper authorization.
Datastage On Cloud Pak Data
CVE-2026-80380 Sep 10, 2026
IBM DataStage on Cloud Pak for Data 5.4.0.0: CSRF Enables Unauthorized Actions IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote attacker to perform unauthorized actions due to cross-site request forgery.
Datastage On Cloud Pak Data
CVE-2026-80434 Sep 10, 2026
IBM DataStage Cloud Pak 5.4.0.0 IDOR Causing Runtime Cache Manipulation & DoS IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to manipulate runtime caches and cause a denial of service due to an insecure direct object reference.
Datastage On Cloud Pak Data
CVE-2026-80424 Sep 10, 2026
IBM DataStage CloudPak Path Traversal 5.4.0.0 Enables Auth Remote File Write IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to create arbitrary files due to path traversal during archive extraction.
Datastage On Cloud Pak Data
CVE-2026-80436 Sep 10, 2026
IBM DataStage Cloud Pak 5.4: Authenticated DOS via RabbitMQ Deletion IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service by deleting arbitrary RabbitMQ queues or exchanges due to improper authorization.
Datastage On Cloud Pak Data
CVE-2026-81204 Sep 10, 2026
IBM Langflow OSS <1.12 - RCE via Graph Construction Code Injection IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code due to code injection during graph construction.
Langflow Oss
CVE-2026-81207 Sep 10, 2026
IBM DataStage CP4D 5.4.0.0 ds-canvas: Auth. tenant controls outbound fetch URLs IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any authenticated tenant with no project membership or role fully controls scheme/host/port/path of an outbound fetch originating from a shared-infrastructure pod, and the WSDL body is reflected verbatim to the caller. The ds-canvas pod sits on the OpenShift overlay with reach to co-tenant services, in-cluster CP4D APIs, and link-local addresses. Scope is Changed, confidentiality High (response-reflecting), integrity Low (GET-only side-effects).
Datastage On Cloud Pak Data
CVE-2026-81210 Sep 10, 2026
IBM DataStage Cloud Pak 5.4 IDOR & Path Traversal via Log Files IBM DataStage on Cloud Pak for Data 5.4.0.0 concatenates three caller-supplied strings into a String.format path on the shared /ds-storage RWX PVC and returns the file with no project ACL pure IDOR plus traversal. Read is constrained to files named job.log/error.log, but DataStage job logs routinely carry connection strings, {dsnextenc} ciphertexts (decryptable via d2-f023), and customer-data row samples. This is the operator's tenant-to-tenant PVC-leakage threat verbatim; MEDIUMHIGH via threat match.
Datastage On Cloud Pak Data
CVE-2026-81211 Sep 10, 2026
IBM Langflow OSS 1.0.0-1.11.5 Remote Code Exec via Custom Component Auth Bypass IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary Python code due to improper authorization of custom components in stored flows.
Langflow Oss
CVE-2026-81941 Sep 10, 2026
IBM Langflow OSS 1.0.0-1.11.5 Authenticated OS Command Execution via MCP Tools IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating system commands on the server at the privilege level of the application process by constructing a flow with an MCP Tools component configured to use a local stdio subprocess transport. This bypasses both the LANGFLOW_CUSTOM_COMPONENT_ADMIN_ONLY and LANGFLOW_BLOCK_CODE_INTERPRETER_COMPONENTS server-side controls intended to prevent exactly this class of access. Successful exploitation could lead to arbitrary command execution, sensitive data exposure (including credentials from the process environment), file system modification, and lateral movement to services reachable from the server.
Langflow Oss
CVE-2026-81213 Sep 10, 2026
IBM Langflow OSS 1.0.01.11.5 URL Validation Remote Info Disclosure IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to obtain sensitive information from internal network resources due to improper validation of user-supplied URLs.
Langflow Oss
CVE-2026-81265 Sep 10, 2026
IBM Langflow OSS 1.0.0-1.11.5: Vulnerable Component Exposes Remote Code Exec IBM Langflow OSS 1.0.0 through 1.11.5.
Langflow Oss
CVE-2026-81268 Sep 10, 2026
IBM Langflow OSS 1.0.0-1.11.5 API Key Session Expiration Bypass IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute flows and obtain sensitive information due to insufficient session expiration of API keys after user deactivation.
Langflow Oss
CVE-2026-81540 Sep 10, 2026
IBM DataStage 5.4.0.0 Path Traversal Enables Auth Tenant Ruleset Overwrite IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to overwrite ruleset files belonging to other tenants due to a path traversal vulnerability.
Datastage On Cloud Pak Data
CVE-2026-81550 Sep 10, 2026
IBM DataStage 5.4.0.0 RCE via improper OS command escaping IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
Datastage On Cloud Pak Data
CVE-2026-81551 Sep 10, 2026
IBM DataStage Cloud Pak 5.4.0 Path Traversal Enables Remote File Write IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to arbitrarily write to or delete files on shared storage due to a path traversal vulnerability.
Datastage On Cloud Pak Data
CVE-2026-81554 Sep 10, 2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 Path Traversal Remote Auth Attack IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability.
Datastage On Cloud Pak Data
CVE-2026-81940 Sep 10, 2026
IBM Langflow OSS <1.12: RCE via unsanitized flow display names IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special characters in flow display names.
Langflow Oss
CVE-2026-82092 Sep 10, 2026
IBM DataStage 5.4.0.0 APT: Absolute-Path Traversal Remote Auth Get Sensitive Info IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability.
Datastage On Cloud Pak Data
CVE-2026-82095 Sep 10, 2026
IBM DataStage Cloud Pak 5.4.0.0 OS Command Injection via Improper Escaping IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
Datastage On Cloud Pak Data
CVE-2026-82097 Sep 10, 2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 SSRF RCE IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to a Server-Side Request Forgery (SSRF) vulnerability.
Datastage On Cloud Pak Data
CVE-2026-82098 Sep 10, 2026
Remote Authenticated Command Injection in IBM DataStage Cloud Pak 5.4.0.0 IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
Datastage On Cloud Pak Data
CVE-2026-82099 Sep 10, 2026
IBM DataStage on Cloud Pak 5.4.0.0: Authenticated RCE via OS Command Injection IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
Datastage On Cloud Pak Data
CVE-2026-82100 Sep 10, 2026
IBM DataStage 5.4.0.0 Path Traversal DoS (Auth) IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability.
Datastage On Cloud Pak Data
CVE-2026-82107 Sep 10, 2026
IBM DS Cloud Pak 5.4 Improper Auth Bypass Remote Data Exfil IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication.
Datastage On Cloud Pak Data
CVE-2026-84889 Sep 10, 2026
IBM Langflow OSS 1.0.0-1.10.3 RCE via Unrestricted Pathname IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.
Langflow Oss
CVE-2026-86087 Sep 10, 2026
IBM Db2 11.5.0-11.5.9/12.1.0-12.1.5 Auth File Write via Crafted Req IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an authenticated user to send a specially crafted request to write arbitrary files on the system.
Db2
CVE-2026-86093 Sep 10, 2026
IBM Db2 11.5/12.1 Stack Buffer Overflow via DRDA Client (CVE-2026-86093) IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer overflow that improperly copies user-controlled data into a fixed-size stack buffer without bounds checking.
Db2
CVE-2026-87958 Sep 10, 2026
IBM Db2 11.5.0-11.5.9/12.1.0-12.1.5 DoS via Privileged User Disabling Functionality IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions.
Db2
CVE-2026-85025 Sep 10, 2026
IBM Langflow OSS 1.0.0-1.11.5 Unauth Remote Code Exec via Public MCP Endpoints IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due to improper enforcement of public-flow security restrictions and session isolation controls.
Langflow Oss
CVE-2026-9667 Sep 10, 2026
IBM WebSphere AS SSRF in 9.0/8.5: remote unauthenticated attack IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) that could allow a remote, unauthenticated attacker to cause the server to send outbound requests to arbitrary endpoints.
WebSphere Application Server
CVE-2026-9176 Sep 10, 2026
IBM WebSphere App Server 8.5/9.0 Auth Bypass Prior to 9.1 IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a security bypass due to improper authentication controls. A local attacker could exploit this vulnerability to escalate privileges and gain unauthorized access to protected resources.
WebSphere Application Server
CVE-2026-9225 Sep 10, 2026
IBM Langflow OSS 1.0.0-1.11.5 AuthC Bypass in File/Read File Component IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an authenticated attacker to access sensitive files belonging to other users due to improper access control in the File/Read File component. When executing flows through the /api/v1/run/advanced/{flow_id} endpoint, the application allows component inputs to reference storage paths using arbitrary user or flow identifiers without verifying ownership. An attacker with lowprivileged authenticated access can supply a crafted file path pointing to another users storage namespace, causing the backend to read and return the contents of files uploaded by other users. This vulnerability bypasses intended authorization checks enforced by the file management API and may result in unauthorized disclosure of sensitive user data.
Langflow Oss
CVE-2026-9327 Sep 10, 2026
IBM WebSphere AppServer 8.5-9.0: Low-Priv Auth Admin Mod Config for Info Leak/DoS IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege administrative role to modify security configuration. This could result in information disclosure or denial of service.
WebSphere Application Server
CVE-2026-9336 Sep 10, 2026
IBM WebSphere App Server 8.5-9.0 DoS via Admin HTTP Endpoint IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted HTTP request to an administrative endpoint. A remote attacker could exploit this vulnerability to cause the server to exhaust filesystem space.
WebSphere Application Server
CVE-2026-9338 Sep 10, 2026
IBM WebSphere App Server 8.5-9.0 DoS via crafted request IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to trigger excessive resource consumption, potentially leading to reduced availability of the affected service.
WebSphere Application Server
CVE-2026-19625 Sep 08, 2026
Quarkus OIDC Introspection Cache Enables CrossTenant Token Use When a Quarkus application has multiple endpoints secured by individual OIDC provider tenants, such as "/oidc-provider1" that is secured by the OIDC Provider 1 and "/oidc-provider2" that is secured by the OIDC Provider 2, and an optional token introspection cache is also enabled, then a valid token issued by the OIDC Provider 1 that can be used to access "/oidc-provider1" can also be used to access "/oidc-provider2" that is secured by another OIDC Provider 2.
Enterprise Build Of Quarkus
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.