IBM
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any IBM product.
RSS Feeds for IBM security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in IBM products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by IBM Sorted by Most Security Vulnerabilities since 2018
Known Exploited IBM Vulnerabilities
The following IBM vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| IBM Aspera Faspex Code Execution Vulnerability |
IBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a YAML deserialization flaw. CVE-2022-47986 Exploit Probability: 100.0% |
February 21, 2023 |
| IBM InfoSphere BigInsights Invalid Input Vulnerability |
Certain APIs within BigInsights can take invalid input that might allow attackers unauthorized access to read, write, modify, or delete data. CVE-2013-3993 Exploit Probability: 5.2% |
May 25, 2022 |
| IBM WebSphere Application Server and Server Hypervisor Edition Code Injection. |
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands CVE-2015-7450 Exploit Probability: 97.7% |
January 10, 2022 |
| IBM Data Risk Manager Arbritary File Download |
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to download arbitrary files from the system. IBM X-Force ID: 180535. CVE-2020-4430 Exploit Probability: 68.5% |
November 3, 2021 |
| IBM Data Risk Manager Authentication Bypass |
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system. IBM X-Force ID: 180532. CVE-2020-4427 Exploit Probability: 70.0% |
November 3, 2021 |
| IBM Data Risk Manager Command Injection |
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM X-Force ID: 180533. CVE-2020-4428 Exploit Probability: 61.7% |
November 3, 2021 |
| IBM Planning Analytics configuration overwrite vulnerability |
IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting. IBM X-Force ID: 172094. CVE-2019-4716 Exploit Probability: 86.4% |
November 3, 2021 |
Of the known exploited vulnerabilities above, 6 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings.
By the Year
In 2026 there have been 444 vulnerabilities in IBM with an average score of 6.6 out of ten. Last year, in 2025 IBM had 563 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in IBM in 2026 could surpass last years number. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.33.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 444 | 6.58 |
| 2025 | 563 | 6.26 |
| 2024 | 503 | 6.44 |
| 2023 | 357 | 6.80 |
| 2022 | 327 | 6.36 |
| 2021 | 443 | 6.10 |
| 2020 | 353 | 6.19 |
| 2019 | 454 | 6.14 |
| 2018 | 451 | 6.24 |
It may take a day or so for new IBM vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent IBM Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-10569 | Jul 30, 2026 |
IBM UrbanCode Deploy 7.x/8.x: Exposure of Sensitive Info in Plugin LogsIBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 is susceptible to an Exposure of Sensitive Information Vulnerability in plugin output logs. This exposure could allow an attacker with access to the logs to potentially obtain senstive values related to that step. |
|
| CVE-2026-11536 | Jul 30, 2026 |
IBM WAS 9.0/8.5 RCE via SOAP/JMX ConnectorIBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector. |
|
| CVE-2026-12946 | Jul 30, 2026 |
IBM Langflow RCE via User Input (v1.0.01.10.0)IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code. |
|
| CVE-2026-13444 | Jul 30, 2026 |
IBM Langflow OSS 1.0.0-1.10.1 Stale Vector Access via Chroma Persist DirIBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access another user's private vector documents by creating their own flow with matching Chroma persist_directory and collection_name values. The attacker receives exact victim content in their workflow output despite having no authorization to read the victim's flow. Additionally, the attacker can pollute the victim's collection by inserting their own documents into the shared namespace. |
|
| CVE-2024-25039 | Jul 30, 2026 |
IBM DOORS Web Access 9.7.2.1-9.7.2.11 Slowloris DoSIBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause the web server to become unresponsive. |
|
| CVE-2024-40683 | Jul 30, 2026 |
IBM Ops Analytics Log Analysis 1.3-1.3.8: Session stays after pw changeIBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4 does not invalidate session after a password chance which could allow an authenticated user to impersonate another user on the system. |
|
| CVE-2026-10545 | Jul 30, 2026 |
IBM Planning Analytics Local Open Redirect (2.1.0-2.1.21) via Crafted URLIBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redirect that allows an attacker to redirect users to arbitrary external websites via a crafted URL. If used in SSO authentication flows, this could result in exposure of session tokens and allow attackers to hijack user sessions. |
|
| CVE-2026-12943 | Jul 30, 2026 |
IBM HMC RCE via Unauth Input v10.3.1050-1064 / v11.1.1110-1112IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink) could allow an unauthenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input. |
|
| CVE-2026-12733 | Jul 30, 2026 |
IBM DataPower Gateway: Remote DoS via Resource ExhaustionIBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper resource limitations. |
And others... |
| CVE-2025-36374 | Jul 30, 2026 |
IBM DataPower Gateway XXE Vulnerability Exposes Sensitive DataIBM DataPower Gateway is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources. |
And others... |
| CVE-2026-12118 | Jul 30, 2026 |
IBM webMethods Integration <10.15 Unauth remote exec via deserializationIBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data. |
|
| CVE-2025-0152 | Jul 30, 2026 |
IBM DOORS & DOORS Web Access 9.6.x9.7.2.x XSS, vuln in Web UIIBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. |
|
| CVE-2026-10535 | Jul 30, 2026 |
IBM Db2 11.5.x/12.1.x Buffer Overflow in setgid helper db2flaccIBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc. |
|
| CVE-2026-10695 | Jul 30, 2026 |
IBM Db2 12.1.x Federated Server DoS via Non-Fenced QueriesIBM Db2 12.1.0 through 12.1.4 federated server is vulnerable to a denial of service when running non fenced federated queries. |
|
| CVE-2026-11904 | Jul 30, 2026 |
Info Disclosure via Detailed Error Messages in IBM Verify ID Access 10.0-11.0.2IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. |
And others... |
| CVE-2026-10700 | Jul 30, 2026 |
Broken Access Control IDOR in IBM Langflow OSS 1.0.0-1.8.4 File APIIBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access control vulnerabilities in its file handling API that allow unauthorized access to user files.The /api/v1/files/images/{flow_id}/{file_name} endpoint does not enforce authentication or authorization checks, allowing unauthenticated remote attackers to retrieve image files associated with any flow by specifying a valid flow_id and file_name.Additionally, the /api/v1/files/download/{flow_id}/{file_name} endpoint requires authentication but fails to properly validate ownership of the requested resource. As a result, an authenticated user can access files belonging to other users by supplying arbitrary identifiers, leading to an authorization bypass (IDOR).Successful exploitation may result in unauthorized disclosure of sensitive data, including files stored in private flows. This issue breaks tenant isolation in multi-user deployments. |
|
| CVE-2026-13435 | Jul 30, 2026 |
IBM Langflow OSS <1.10.2 Improper Input Validation in PythonREPL SandboxIBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation. |
|
| CVE-2026-12942 | Jul 30, 2026 |
IBM Langflow OSS 1.0.0-1.10.1 Dir Traversal via dotdot URLIBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to view arbitrary files on the system. |
|
| CVE-2026-12945 | Jul 30, 2026 |
IBM Langflow OSS 1.0.0-1.10.1 Auth Bypass: Log Retrieve & Build EndpointsIBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs through improper access control on log retrieval and unauthenticated build endpoints. |
|
| CVE-2026-12940 | Jul 30, 2026 |
Unauth RCE in IBM Langflow OSS 1.0.0-1.10.1 via env var injectionIBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The vulnerability exists in src/lfx/src/lfx/base/mcp/util.py where the DANGEROUS_ENV_VARS blocklist fails to include SHELLOPTS , BASHOPTS , and PS4 environment variables. |
|
| CVE-2026-11885 | Jul 30, 2026 |
IBM PowerVM Hypervisor Crash via CVE-2026-11885 (FW950-1110)IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H1 A carefully crafted OS hypervisor call can cause the PowerVM hypervisor to crash or compromise OS memory integrity. |
|
| CVE-2026-9322 | Jul 30, 2026 |
IBM WAS DoS via Crafted HTTP Request in 8.5-9.0 and Liberty 17-26IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted HTTP request. |
|
| CVE-2026-10842 | Jul 30, 2026 |
IBM WebSphere App Server 8.5/9.0 & Liberty 17.0.0.3-26.0.0.7 Bypass Security ConstraintsIBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 Traditional and Liberty could allow a remote attacker to bypass security constraints. |
|
| CVE-2025-36431 | Jul 30, 2026 |
IBM Sterling B2B/File Gateway 6.2.2.0-6.2.2.0_1 XSS via Auth UserIBM Sterling B2B Integrator 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.2.0 through 6.2.2.0_1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. |
|
| CVE-2025-36298 | Jul 30, 2026 |
IBM Sterling B2B Integrator 6.1.2.x-6.2.2.x XSS in Ebics server componentIBM Sterling B2B Integrator 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 Ebics server component is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. |
|
| CVE-2026-11897 | Jul 30, 2026 |
IBM WAS Liberty 17.0.0.3 DoS via Crafty Request (Memory Exhaustion)IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. |
|
| CVE-2026-12947 | Jul 30, 2026 |
Local Log Information Disclosure in IBM ACE 12.0.1.0-12.0.12.27 & 13.0.1.0-13.0.7.2IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 stores potentially sensitive information in log files that could be read by a local user. |
|
| CVE-2026-11980 | Jul 30, 2026 |
IBM Aspera Desktop App 1.0.5-1.0.19 DLL Loading RCEIBM Aspera Desktop App 1.0.5 through 1.0.19 can allow arbitrary code execution by loading DLL files at start-up. |
|
| CVE-2026-11707 | Jul 30, 2026 |
IBM Tivoli SA AM 4.1: XSS in Admin Console Login PageIBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the administrative console login page. |
|
| CVE-2026-11383 | Jul 30, 2026 |
IBM Tivoli SAAM 4.1 & WebSphere App Server: XSS in Admin Console (CVE-2026-11383)IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by cross-site scripting in the Administrative Console. |
|
| CVE-2026-14980 | Jul 30, 2026 |
IBM WSA Liberty 17-26 CSRF SSRF via collectiveControllerIBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to perform SSRF attacks with elevated privileges when the collectiveController-1.0 feature is enabled. |
|
| CVE-2026-15435 | Jul 30, 2026 |
IBM App Connect Enterprise 12/13 Directory Traversal (13.0.7.2)IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to write arbitrary files on the system. |
|
| CVE-2026-14522 | Jul 30, 2026 |
IBM App Connect Enterprise 12-13.0 CRLF RCE 2026-14522IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to execute arbitrary commands due to improper neutralization of CRLF characters. |
|
| CVE-2026-14519 | Jul 30, 2026 |
IBM App Connect EE <13.0.7.2 / <12.0.12.27 Path Trv. File ReadIBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to read arbitrary files due to a path traversal vulnerability. |
|
| CVE-2026-16308 | Jul 30, 2026 |
IBM Quarkus REST DoS via Unbounded MIME Header Accum (3.27,3.33)IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 through 3.33.2.SP2 Quarkus REST could allow a remote attacker to cause a denial of service due to unbounded accumulation of multipart MIME part-header bytes. |
|
| CVE-2026-2482 | Jul 29, 2026 |
XSS CSRF in IBM WebSphere Liberty 17.0.0.3-26.0.0.8IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. |
|
| CVE-2026-14529 | Jul 29, 2026 |
IBM WSS/LIBERTY SIP SSRF via sipServlet-1.1 pre-26.0.0.9IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled. |
|
| CVE-2026-13442 | Jul 28, 2026 |
IBM Langflow OSS 1.0-1.10.1 FAISS reuse causes cross-user data disclosureIBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace to access owner-only vector content and influence later query results. This causes cross-user information disclosure and limited integrity impact through persistent poisoning of returned results. |
|
| CVE-2026-13463 | Jul 28, 2026 |
IBM Cloud Pak System 2.3.5.0 Log Credential DisclosureIBM Cloud Pak System 2.3.5.0 could allow a local attacker to obtain sensitive information due to the insertion of credentials into log files. |
|
| CVE-2026-14446 | Jul 28, 2026 |
Broken Access Control in IBM WebSphere App Server 8.5/9.0 Admin ConsoleIBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console. |
|
| CVE-2026-14515 | Jul 28, 2026 |
IBM WAS 8.5/9.0 Traditional XSS VulnerabilityIBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to conduct a cross-site scripting attack. |
|
| CVE-2026-14512 | Jul 28, 2026 |
IBM WebSphere App Server 9.0/8.5 pre-auth unsafe deserializationIBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code. |
|
| CVE-2026-14528 | Jul 28, 2026 |
IBM WebSphere AppServer 8.5/9.0 Remote Info DisclosureIBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive information. |
|
| CVE-2026-14893 | Jul 28, 2026 |
IBM Instana Node.js tracer @instana/core 6.2.1 prototype pollutionIBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana Node.js tracer component @instana/core version 6.2.1 is vulnerable to prototype pollution through its configuration normalization API. |
|
| CVE-2026-14958 | Jul 28, 2026 |
IBM Aspera Faspex 5.0.0-5.0.15.4 Arbitrary Code Exec via Unquoted Shell InterpIBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation. |
|
| CVE-2026-14959 | Jul 28, 2026 |
IBM Aspera Faspex 5.0.0-5.0.15.4 Shell Command Injection Allows Remote Code ExecIBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to shell command injection. |
|
| CVE-2026-14973 | Jul 28, 2026 |
IBM Aspera Desktop App 1.0.5-1.0.19 allows arbitrary file write outside destinationIBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination. |
|
| CVE-2026-14974 | Jul 28, 2026 |
IBM WebSphere AppServer 8.5/9.0 RCE via Unsafe DeserializationIBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data. |
|
| CVE-2026-14976 | Jul 28, 2026 |
IBM WebSphere Liberty RCE via collectiveCtrl-1.0 (v17.0.0.3-26.0.0.8)IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature enabled. |
|
| CVE-2026-14981 | Jul 28, 2026 |
IBM WebSphere WAS & Liberty DoS via HTTP Channel Unbounded Resource AllocationIBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are affected by a denial of service vulnerability in the HTTP channel due to unbounded allocation of resources without limits. |
|