IBM
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any IBM product.
RSS Feeds for IBM security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in IBM products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by IBM Sorted by Most Security Vulnerabilities since 2018
Known Exploited IBM Vulnerabilities
The following IBM vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| IBM Langflow Code Injection Vulnerability |
Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments. CVE-2026-9198 |
August 4, 2026 |
| IBM Aspera Faspex Code Execution Vulnerability |
IBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a YAML deserialization flaw. CVE-2022-47986 Exploit Probability: 100.0% |
February 21, 2023 |
| IBM InfoSphere BigInsights Invalid Input Vulnerability |
Certain APIs within BigInsights can take invalid input that might allow attackers unauthorized access to read, write, modify, or delete data. CVE-2013-3993 Exploit Probability: 5.2% |
May 25, 2022 |
| IBM WebSphere Application Server and Server Hypervisor Edition Code Injection. |
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands CVE-2015-7450 Exploit Probability: 97.7% |
January 10, 2022 |
| IBM Data Risk Manager Arbritary File Download |
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to download arbitrary files from the system. IBM X-Force ID: 180535. CVE-2020-4430 Exploit Probability: 68.5% |
November 3, 2021 |
| IBM Data Risk Manager Authentication Bypass |
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system. IBM X-Force ID: 180532. CVE-2020-4427 Exploit Probability: 70.0% |
November 3, 2021 |
| IBM Data Risk Manager Command Injection |
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM X-Force ID: 180533. CVE-2020-4428 Exploit Probability: 61.7% |
November 3, 2021 |
| IBM Planning Analytics configuration overwrite vulnerability |
IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting. IBM X-Force ID: 172094. CVE-2019-4716 Exploit Probability: 86.4% |
November 3, 2021 |
Of the known exploited vulnerabilities above, 6 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings.
By the Year
In 2026 there have been 636 vulnerabilities in IBM with an average score of 6.8 out of ten. Last year, in 2025 IBM had 563 security vulnerabilities published. That is, 73 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.51.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 636 | 6.76 |
| 2025 | 563 | 6.26 |
| 2024 | 503 | 6.44 |
| 2023 | 357 | 6.80 |
| 2022 | 327 | 6.36 |
| 2021 | 443 | 6.10 |
| 2020 | 353 | 6.19 |
| 2019 | 454 | 6.14 |
| 2018 | 451 | 6.24 |
It may take a day or so for new IBM vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent IBM Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-18554 | Aug 14, 2026 |
IBM Db2 Mirror for i 7.47.6 Pathname Lmt Bypass Allows Info DisclosureIBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory. |
|
| CVE-2026-18178 | Aug 14, 2026 |
IBM Db2 Mirror for i 7.47.6 | Path Traversal => Remote File DeleteIBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to delete arbitrary files due to path traversal. |
|
| CVE-2026-17227 | Aug 14, 2026 |
Remote Auth Bypass in IBM Db2 Mirror for i (7.4-7.6) via SQL InjectionIBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper neutralization of special elements used in an SQL command. |
|
| CVE-2026-17209 | Aug 14, 2026 |
IBM Db2 Mirror for i 7.4-7.6 XSS Remote Auth ExecIBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to execute arbitrary scripts due to cross-site scripting. |
|
| CVE-2026-17186 | Aug 14, 2026 |
IBM Db2 Mirror for i 7.6 Remote CL Cmd Exec via Improper EscapingIBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to improper neutralization of special elements in a command. |
|
| CVE-2026-17184 | Aug 14, 2026 |
IBM Db2 Mirror for i 7.4-7.6 RCE via External File PathIBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external control of file name or path. |
|
| CVE-2026-17182 | Aug 14, 2026 |
IBM Db2 Mirror for i Auth Bypass via Improper URI Path Validation 7.47.6IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensitive information due to improper validation of request URI path segments. |
|
| CVE-2026-17181 | Aug 14, 2026 |
IBM Db2 Mirror for i 7.47.6 Path Traversal Remote File WriteIBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due to path traversal. |
|
| CVE-2026-17179 | Aug 14, 2026 |
IBM Db2 Mirror for i 7.4-7.6 Remote Cmd Inject DoSIBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to cause a denial of service due to command injection. |
|
| CVE-2026-17177 | Aug 14, 2026 |
DoS via Uncontrolled Recursion in IBM DB2 Mirror for i 7.4-7.6IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to uncontrolled recursion. |
|
| CVE-2026-17175 | Aug 14, 2026 |
IBM Db2 Mirror for i, v7.4-7.6 Improper Auth Enforcement Remote Info DisclosureIBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enforcement. |
|
| CVE-2026-17173 | Aug 14, 2026 |
IBM Db2 Mirror for i 7.47.6 Path Traversal Remote AuthIBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of file paths. |
|
| CVE-2026-17081 | Aug 14, 2026 |
IBM Db2 Mirror i 7.[46] Remote File Write via Unrestricted PathIBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write arbitrary files due to improper limitation of a pathname to a restricted directory. |
|
| CVE-2026-17079 | Aug 14, 2026 |
IBM Db2 Mirror for i <7.7: Authenticated Remote Bypass via ParamIBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to the ability to disable server-side input validation via a request parameter. |
|
| CVE-2026-16915 | Aug 14, 2026 |
Remote Authenticated Info Disclosure in IBM Db2 Mirror for i 7.4-7.6IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper input validation. |
|
| CVE-2026-16905 | Aug 14, 2026 |
IBM Db2 Mirror for i 7.47.6 Remote Auth Improper Auth DisclosureIBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication. |
|
| CVE-2026-16879 | Aug 14, 2026 |
IBM Db2 Mirror for i 7.47.6 Remote Auth Bypass via Improper AuthorizationIBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization using user-supplied input. |
|
| CVE-2026-16708 | Aug 14, 2026 |
IBM Db2 Mirror for i 7.4-7.6 Remote Config Control for Data LeakageIBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to external control of system configuration. |
|
| CVE-2026-19483 | Aug 13, 2026 |
IBM Storage Scale 5.2.3.0-5.2.3.8/6.0.0.0-6.0.1.0 GUI Log Exposes PasswordsIBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 Secrets may be disclosed in log files in IBM Storage Scale Management GUI The admin password is logged into the GUI log of IBM Storage Scale Systems Deploy and Upgrade from GUI. Secrets may be disclosed in information related to exceptions in IBM Storage Scale Management GUI. |
|
| CVE-2026-19297 | Aug 13, 2026 |
IBM Langflow OSS 1.01.9.6 Unchecked Auth Attempts Expose AccountsIBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authentication attempts. |
|
| CVE-2026-18715 | Aug 13, 2026 |
Remote Authenticated Info Disclosure via XML External Entities in IBM i 7.6-7.3IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper processing of XML external entities. |
|
| CVE-2026-18671 | Aug 13, 2026 |
IBM i 7.6/7.5/7.4/7.3 NetServer Int Overflow DoSIBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to force a NetServer server thread exception, caused by an integer overflow during bounds checking in request processing. The attacker could exploit this vulnerability to cause a temporary denial of service. |
|
| CVE-2026-18511 | Aug 13, 2026 |
IBM i 7.6-7.3 JSSE provider stack overflow via TLS sessionIBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to generate a stack-based buffer overflow in the Native IBM i JSSE provider, caused by improper bounds checking during TLS session establishment. A local attacker could overflow a fixed-length buffer and execute arbitrary code on the system or cause the JVM process to crash. |
|
| CVE-2026-18509 | Aug 13, 2026 |
IBM i 7.x local auth privilege escalation via Navigator for i debuggerIBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to gain privilege escalation via the Navigator for i debugger. This could allow the attacker to access or manipulate sensitive data on the system, or create new profiles with elevated privileges on the IBM i system. |
|
| CVE-2026-18249 | Aug 13, 2026 |
IBM i 7.6/7.5/7.4/7.3 Exp Lev via Java Ptr Validation FaultIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improper validation of pointers read from Java-controlled addresses. |
|
| CVE-2026-18193 | Aug 13, 2026 |
IBM i 7.x CVE-2026-18193: Remote Bypass via Addr ValidationIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of user-controlled addresses. |
|
| CVE-2026-18101 | Aug 13, 2026 |
IBM i 7.x Thread Authority Swap Local Priv EscIBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper management of thread authority swaps. |
|
| CVE-2026-18086 | Aug 13, 2026 |
IBM i 7.6-7.3 Local Arbitrary Code/DoS via Improper Bounds CheckIBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code or cause a denial of service due to improper bounds checking. |
|
| CVE-2026-18077 | Aug 13, 2026 |
IBM i 7.x Stack Buffer Overflow Culminates in DoS via Remote AttackIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a stack-based buffer overflow. |
|
| CVE-2026-18068 | Aug 13, 2026 |
IBM i 7.6/7.5/7.4/7.3 Info Disclosure via Byte-Count ConfusionIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to a byte-count and element-count confusion. |
|
| CVE-2026-18020 | Aug 13, 2026 |
IBM i Off-by-One Bounds Checking DoS in 7.6/7.5/7.4/7.3IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an off-by-one error in bounds checking. |
|
| CVE-2026-17649 | Aug 13, 2026 |
IBM i OOB Read Vulnerability (CVE-2026-17649)IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read. |
|
| CVE-2026-17502 | Aug 13, 2026 |
IBM i 7.6-7.3 Remote DoS via OutofBounds WriteIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds write. |
|
| CVE-2026-17482 | Aug 13, 2026 |
IBM Doc Offline 1.01.4.1 RCE via improper file path controlIBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper control of file paths. |
|
| CVE-2026-17481 | Aug 13, 2026 |
IBM Doc Offline <1.5.0: Remote ACE via Log InjectionIBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper output neutralization for logs. |
|
| CVE-2026-17476 | Aug 13, 2026 |
IBM i 7.6/7.5/7.4/7.3 Remote DoS via improper buffer writeIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an improper buffer write. |
|
| CVE-2026-17473 | Aug 13, 2026 |
IBM Documentation Offline 1.0.0-1.4.1 Path Traversal Arbitrary File ReadIBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to read arbitrary files due to improper limitation of a pathname to a restricted directory. |
|
| CVE-2026-17438 | Aug 13, 2026 |
IBM i 7.6-7.3 Local Privilege Escalation via Improper Privilege ManagementIBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to obtain sensitive information or modify data due to improper privilege management. |
|
| CVE-2026-17468 | Aug 13, 2026 |
IBM Documentation Offline 1.0.0-1.4.1: Hardcoded key allows session token forgeIBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to forge valid session tokens due to the use of a hardcoded cryptographic key. |
|
| CVE-2026-17075 | Aug 13, 2026 |
IBM i Auth Token Validation Flaw 7.6/7.5/7.4/7.3 Remote Info DisclosureIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information and perform unauthorized operations due to improper validation of authentication tokens. |
|
| CVE-2026-17272 | Aug 13, 2026 |
IBM i Remote DoS via Buffer Overflow (v7.3-7.6)IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a buffer overflow. |
|
| CVE-2026-17226 | Aug 13, 2026 |
IBM i 7.6: OOB Read Enables Remote Authenticated Info Leakage & DoSIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information or cause a denial of service due to an out-of-bounds read. |
|
| CVE-2026-17216 | Aug 13, 2026 |
IBM i (pre-8.0) DRDA LO header integer error leads to DoSIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an integer error when processing DRDA large-object headers. |
|
| CVE-2026-17212 | Aug 13, 2026 |
IBM i OOB Read DoS 7.6, 7.5, 7.4, 7.3IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds read. |
|
| CVE-2026-17101 | Aug 13, 2026 |
IBM i 7.3-7.6 Auth Bypass RCE & Info LeakIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code or obtain sensitive information due to improper authentication. |
|
| CVE-2026-17099 | Aug 13, 2026 |
IBM i 7.67.3 Improper Auth Enables Remote Info DisclosureIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to improper authentication. |
|
| CVE-2026-17088 | Aug 13, 2026 |
IBM i 7.67.3 Path Traversal Enables Remote Info DisclosureIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a path traversal vulnerability. |
|
| CVE-2026-17078 | Aug 13, 2026 |
IBM i 7.x DoS via Resource ExhaustionIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to resource exhaustion. |
|
| CVE-2026-17077 | Aug 13, 2026 |
IBM i 7.37.6 Remote DoS via Uninitialized VariableIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to the use of an uninitialized variable. |
|
| CVE-2026-17076 | Aug 13, 2026 |
IBM i Pre-7.7 DRDA/DDM Resync Defect Causing Remote DOSIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper processing of DRDA and DDM resynchronization requests. |
|