CVE-2026-18490 is a vulnerability in IBM Financial Transaction Manager Ftmfor Redhat Openshift
Published on September 23, 2026
IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to unauthenticated remote code execution via Java native deserialization on the PayDir Business Rules Manager RMI SSL endpoint (BrmRMISSLServerSocketFactory.java:95, EP8). An adjacent-network attacker can deliver a crafted serialized payload to achieve arbitrary code execution, exposing all PayDir credentials and enabling manipulation of payment business rules.
Vulnerability Analysis
Weakness Type
What is a Marshaling, Unmarshaling Vulnerability?
The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
CVE-2026-18490 has been classified to as a Marshaling, Unmarshaling vulnerability or weakness.
Products Associated with CVE-2026-18490
Want to know whenever a new CVE is published for IBM Financial Transaction Manager Ftmfor Redhat Openshift? stack.watch will email you.
Affected Versions
IBM Financial Transaction Manager (FTM) for RedHat OpenShift:- Version 4.0.6.0, <= 4.0.10.0 is affected.