IBM
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any IBM product.
RSS Feeds for IBM security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in IBM products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by IBM Sorted by Most Security Vulnerabilities since 2018
Known Exploited IBM Vulnerabilities
The following IBM vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| IBM Langflow Code Injection Vulnerability |
Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments. CVE-2026-9198 |
August 4, 2026 |
| IBM Aspera Faspex Code Execution Vulnerability |
IBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a YAML deserialization flaw. CVE-2022-47986 Exploit Probability: 100.0% |
February 21, 2023 |
| IBM InfoSphere BigInsights Invalid Input Vulnerability |
Certain APIs within BigInsights can take invalid input that might allow attackers unauthorized access to read, write, modify, or delete data. CVE-2013-3993 Exploit Probability: 5.2% |
May 25, 2022 |
| IBM WebSphere Application Server and Server Hypervisor Edition Code Injection. |
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands CVE-2015-7450 Exploit Probability: 97.8% |
January 10, 2022 |
| IBM Data Risk Manager Arbritary File Download |
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to download arbitrary files from the system. IBM X-Force ID: 180535. CVE-2020-4430 Exploit Probability: 68.5% |
November 3, 2021 |
| IBM Data Risk Manager Authentication Bypass |
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system. IBM X-Force ID: 180532. CVE-2020-4427 Exploit Probability: 70.0% |
November 3, 2021 |
| IBM Data Risk Manager Command Injection |
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM X-Force ID: 180533. CVE-2020-4428 Exploit Probability: 61.7% |
November 3, 2021 |
| IBM Planning Analytics configuration overwrite vulnerability |
IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting. IBM X-Force ID: 172094. CVE-2019-4716 Exploit Probability: 86.4% |
November 3, 2021 |
Of the known exploited vulnerabilities above, 6 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings.
By the Year
In 2026 there have been 1131 vulnerabilities in IBM with an average score of 7.0 out of ten. Last year, in 2025 IBM had 563 security vulnerabilities published. That is, 568 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.75.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 1131 | 7.00 |
| 2025 | 563 | 6.26 |
| 2024 | 503 | 6.44 |
| 2023 | 357 | 6.80 |
| 2022 | 327 | 6.36 |
| 2021 | 443 | 6.10 |
| 2020 | 353 | 6.19 |
| 2019 | 454 | 6.14 |
| 2018 | 451 | 6.24 |
It may take a day or so for new IBM vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent IBM Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-84239 | Sep 18, 2026 |
IBM Guardium DP 12.2 SQLi Remote Authenticated Data LeakageIBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command. |
|
| CVE-2026-84241 | Sep 18, 2026 |
IBM Guardium Data Protection 12.2 Auth Bypass VulnerabilityIBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper authorization. |
|
| CVE-2026-84108 | Sep 18, 2026 |
IBM Guardium Data Protection 12.2 RCE via unsanitized input in web pageIBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of input during web page generation. |
|
| CVE-2026-84106 | Sep 18, 2026 |
IBM Guardium DP 12.2 Web UI RCE via improper input neutralizationIBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation. |
|
| CVE-2026-84105 | Sep 18, 2026 |
IBM Guardium Data Protection 12.2 SQL Injection via Improper NeutralizationIBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command. |
|
| CVE-2026-84089 | Sep 18, 2026 |
IBM Guardium DP 12.2 Local Priv Esc via Improper Priv MgmtIBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management. |
|
| CVE-2026-84086 | Sep 18, 2026 |
IBM Guardium 12.2 Pathname Handling Remote Auth Attacker Code ExecIBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory. |
|
| CVE-2026-84085 | Sep 18, 2026 |
IBM Guardium Data Protection 12.2 Remote Execution via OS Command InjectionIBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command. |
|
| CVE-2026-84084 | Sep 18, 2026 |
CVE-2026-84084: IBM Guardium Data Protection 12.2 CSRF allows remote bypassIBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery (CSRF) vulnerability. |
|
| CVE-2026-84083 | Sep 18, 2026 |
IBM Guardium Data Protection 12.2 SUID nmap_wrapper LPE VulnerabilityIBM Guardium Data Protection 12.2 is vulnerable to local privilege escalation via the SUID-root nmap_wrapper binary on the Collector appliance. A local attacker with low-privileged access to the Collector can exploit insufficient argument validation in the SUID binary to execute arbitrary commands as root, resulting in full compromise of the Collector appliance. |
|
| CVE-2026-84082 | Sep 18, 2026 |
IBM Guardium Data Protection 12.2 SQL Injection RCEIBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command. |
|
| CVE-2026-84081 | Sep 18, 2026 |
IBM Guardium DP 12.2 Certificate Validation BypassIBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper certificate validation. |
|
| CVE-2026-84078 | Sep 18, 2026 |
IBM Guardium DP 12.2: Unauth Access via LoadBalancerServletIBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet. An unauthenticated user can access privileged load-balancer operations, potentially resulting in unauthorized actions and impact to the integrity and availability of the affected system. |
|
| CVE-2026-84077 | Sep 18, 2026 |
IBM Guardium DP 12.2 XSRF Bypass Security RestrictionsIBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery vulnerability. |
|
| CVE-2026-84076 | Sep 18, 2026 |
IBM Guardium Data Protection 12.2 Improper Authorization (CVE202684076)IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization. |
|
| CVE-2026-84075 | Sep 18, 2026 |
Auth bypass via ChangeTrackerServlet in IBM Guardium DP 12.2IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to missing authentication for the ChangeTrackerServlet. |
|
| CVE-2026-84074 | Sep 18, 2026 |
RCE via Improper Input Neutralization in IBM Guardium DP 12.2IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation. |
|
| CVE-2026-84073 | Sep 18, 2026 |
IBM Guardium 12.2 SQL Injection via Improper Neutralization of Special ElementsIBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command. |
|
| CVE-2026-84071 | Sep 18, 2026 |
IBM Guardium 12.2 OS Command Injection via Universal Connector UploadIBM Guardium Data Protection 12.2 is vulnerable to OS command injection in the Universal Connector plugin upload functionality. A privileged authenticated attacker can provide a malicious filename that is incorporated into a shell command executed by the application, potentially resulting in arbitrary command execution with root-level privileges. |
|
| CVE-2026-84070 | Sep 18, 2026 |
IBM Guardium 12.2 RCE via Improper Input Neutralization in Web GenIBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation. |
|
| CVE-2026-84036 | Sep 18, 2026 |
IBM Guardium DP 12.2 Auth Bypass (Remote Authenticated Attacker)IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization. |
|
| CVE-2026-84064 | Sep 18, 2026 |
IBM Guardium DP 12.2 Authenticated SQL Injection VulnerabilityIBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command. |
|
| CVE-2026-84034 | Sep 18, 2026 |
IBM Guardium Dp 12.2 Hardcoded Credentials in obstore BinaryIBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulnerability in the hardware_assess/obstore binaries. A low-privileged authenticated user can recover hardcoded product master secrets, potentially resulting in unauthorized access to the internal database and compromise of sensitive system information. |
|
| CVE-2026-84031 | Sep 18, 2026 |
IBM Guardium Data Protection 12.2 RCE via Web Page XSSIBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation. |
|
| CVE-2026-82967 | Sep 18, 2026 |
Auth Bypass in IBM Guardium Data Protection 12.2 IPACL ExemptionIBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthenticated remote attacker to bypass IP-based access controls and access the Guardium management interface. |
|
| CVE-2026-82896 | Sep 18, 2026 |
IBM Guardium DP 12.2 PT PathTraversal Remote AuthenticatedIBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to traverse directories on the system due to a path traversal vulnerability. |
|
| CVE-2026-82893 | Sep 18, 2026 |
IBM Guardium Data Protection 12.2 Local Priv Escalation via Improper Priv MgmtIBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management. |
|
| CVE-2026-82892 | Sep 18, 2026 |
Remote Exec via OS Cmd in IBM Guardium DP 12.2 (CVE-2026-82892)IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. |
|
| CVE-2026-82890 | Sep 18, 2026 |
Remote Authenticated JS Exec via XSS in IBM Guardium Data Protection 12.2IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary JavaScript code due to improper neutralization of input during web page generation. |
|
| CVE-2026-82887 | Sep 18, 2026 |
OS Command Injection in IBM Guardium 12.2 via Improper InputIBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. |
|
| CVE-2026-82885 | Sep 18, 2026 |
IBM Guardium Data Protection 12.2 REST API Auth Bypass Elevates PrivilegesIBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to gain elevated privileges due to missing authorization in the REST API. |
|
| CVE-2026-82832 | Sep 18, 2026 |
Remote Code Exec in IBM Guardium DP 12.2 via Improper Input NeutralizationIBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation. |
|
| CVE-2026-82340 | Sep 18, 2026 |
IBM Guardium Data Protection 12.2 Unauthenticated Deserialization (CAS Listener)IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled reflective method dispatch in the Change Audit System (CAS) listener. A network attacker able to reach TCP port 16017 may submit crafted serialized messages and potentially cause unintended code execution in the Guardium appliance. |
|
| CVE-2026-81937 | Sep 18, 2026 |
IBM Guardium DP 12.2 CLI Command Injection via import remotelog_configIBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the import remotelog_config file CLI command. A highly privileged authenticated user can inject shell commands through the filename parameter, potentially resulting in arbitrary command execution with root privileges and impact to the confidentiality, integrity, and availability of the affected system. |
|
| CVE-2026-81933 | Sep 18, 2026 |
IBM Guardium DP 12.2 SQLi in Analytic Grid Service Handler (Auth Intr)IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Analytic Grid Service Handler. A low-privileged authenticated user can inject SQL statements through the analytic cases grid endpoint, potentially resulting in unauthorized access to sensitive data and impact to the confidentiality, integrity, and availability of the affected system. |
|
| CVE-2026-81669 | Sep 18, 2026 |
IBM Guardium Data Protection 12.2 CLI Command Injection via CSR Wildcard AliasIBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the create csr wildcard CLI command. An authenticated privileged CLI user can inject arbitrary shell commands through the alias input, resulting in command execution with root privileges. |
|
| CVE-2026-81657 | Sep 18, 2026 |
IBM Guardium DP 12.2 RCE via Untrusted DeserializationIBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data. |
|
| CVE-2026-81656 | Sep 18, 2026 |
IBM Guardium 12.2 SQLi in New Query Builder RESTIBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the New Query Builder REST Processor. A low-privileged authenticated user can inject SQL statements through the newQueryBuilder REST endpoint, potentially resulting in unauthorized access to data and impact to the confidentiality, integrity, and availability of the affected system. |
|
| CVE-2026-81626 | Sep 18, 2026 |
IBM Guardium 12.2 SQLi via LBServlet data breachIBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Load Balancer Groups component. An unauthenticated user can inject SQL statements through the Load Balancer Servlet endpoint, potentially resulting in unauthorized access to data and impact to the confidentiality, integrity, and availability of the affected system. |
|
| CVE-2026-81623 | Sep 18, 2026 |
IBM Guardium DP 12.2 Authenticated Remote Command Exec via Input ValidationIBM Guardium Data Protection 12.2 could allow an authenticated user to execute arbitrary commands with low user privileges on the system due to improper validation of user supplied input. |
|
| CVE-2026-80442 | Sep 18, 2026 |
IBM Guardium Data Protection 12.2 ExportCertificate Auth'd OS Command InjectionIBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection vulnerability in the exportCertificate functionality. Successful exploitation could allow an attacker to execute unauthorized commands and impact the confidentiality, integrity, and availability of the affected system. |
|
| CVE-2026-80441 | Sep 18, 2026 |
IBM Guardium Data Protection 12.2 SQL injection in generateInsertQueryIBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the generateInsertQuery functionality of change-tracker-data.sql. A remote attacker could inject malicious SQL that is subsequently processed by the application, potentially resulting in compromise of the confidentiality, integrity, and availability of the affected system. |
|
| CVE-2026-75878 | Sep 18, 2026 |
IBM Sterling FG Auth Bypass via Unvalidated SSO HeaderIBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated session due to improper authentication via an unvalidated SSO header. |
|
| CVE-2026-18869 | Sep 18, 2026 |
IBM i 7.6/7.5/7.4/7.3: Remote AuthUser Bypass via FTP PORT/EPRTIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions and access internal network services due to improper validation of FTP PORT and EPRT commands. |
|
| CVE-2026-17619 | Sep 18, 2026 |
IBM Platform RTM SQLi: Remote Attacker Can Manipulate DBIBM Platform RTM is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. |
|
| CVE-2026-17262 | Sep 18, 2026 |
IBM i 7.6-7.3 Local DoS via Improper FTP Auth ValidationIBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to improper validation of FTP authentication commands. |
|
| CVE-2026-11727 | Sep 18, 2026 |
IBM MQ for HPE NonStop 8.1.0-8.1.0.40 C Client AMS Validation Remote DoS/CodeIBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of queue manager responses when requesting AMS policy data. |
|
| CVE-2026-11726 | Sep 18, 2026 |
IBM MQ for HPE NonStop 8.1.0-8.1.0.40 Header Offset DisclosureIBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to obtain sensitive information or cause a denial of service due to improper validation of message header offset values. |
|
| CVE-2026-11725 | Sep 18, 2026 |
IBM MQ int overflow in MQINQ => DoS / remote code execIBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in MQINQ request processing. |
|
| CVE-2026-11722 | Sep 18, 2026 |
HTTP Request Smuggling in IBM WebSphere Application ServerIBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability. |
|