application gateway operator vulnerability (CVE-2026-17617)
CRITICALIBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specified in custom resources.

IBM product CVE coverage for enterprise software, middleware, security tooling, cloud services, and infrastructure components.
Watch items
Showing the 20 most recent items, newest first. Each row links to the official advisory.
20 rows · sorted newest first
Operations viewIBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specified in custom resources.
IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes.
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input.
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event processing pipeline ( q1labs_core.jar ). When at least one log source type is configured to use XML-format property autodetection, the system processes XML-formatted syslog events sent to port 514 (UDP/TCP) without authentication.
Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.
IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc.
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to perform SSRF attacks with elevated privileges when the collectiveController-1.0 feature is enabled.
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to execute arbitrary commands due to improper neutralization of CRLF characters.
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled.
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP request smuggling.
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature enabled.
IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data.
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to shell command injection.
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation.
IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive information.
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request.
IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset functionality.
| Alert | Exposure | Status | Published | Source |
|---|---|---|---|---|
application gateway operator vulnerability (CVE-2026-17617)IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specified in custom resources. application gateway operator | CRITICALCVE-2026-17617 Watch | watch | Aug 5, 2026, 12:16 PM | NVDOpen source |
websphere application server vulnerability (CVE-2026-8400)IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes. websphere application server | CRITICALCVE-2026-8400 Watch | watch | Aug 5, 2026, 11:17 AM | NVDOpen source |
qradar security information and event manager vulnerability (CVE-2026-13477)IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input. qradar security information and event manager | HIGHCVE-2026-13477 Watch | watch | Aug 5, 2026, 11:16 AM | NVDOpen source |
qradar security information and event manager vulnerability (CVE-2026-10025)IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event processing pipeline ( q1labs_core.jar ). When at least one log source type is configured to use XML-format property autodetection, the system processes XML-formatted syslog events sent to port 514 (UDP/TCP) without authentication. qradar security information and event manager | CRITICALCVE-2026-10025 Watch | watch | Aug 5, 2026, 11:16 AM | NVDOpen source |
IBM Langflow Code Injection VulnerabilityLangflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments. Langflow | criticalCVE-2026-9198 Critical | active | Aug 3, 2026, 7:00 PM | CISA KEVOpen source |
webmethods integration vulnerability (CVE-2026-12118)IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data. webmethods integration | CRITICALCVE-2026-12118 Watch | watch | Jul 30, 2026, 2:17 PM | NVDOpen source |
db2 vulnerability (CVE-2026-10535)IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc. db2 | HIGHCVE-2026-10535 Watch | watch | Jul 30, 2026, 2:17 PM | NVDOpen source |
websphere application server vulnerability (CVE-2026-14980)IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to perform SSRF attacks with elevated privileges when the collectiveController-1.0 feature is enabled. websphere application server | HIGHCVE-2026-14980 Watch | watch | Jul 30, 2026, 10:16 AM | NVDOpen source |
app connect enterprise vulnerability (CVE-2026-14522)IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to execute arbitrary commands due to improper neutralization of CRLF characters. app connect enterprise | CRITICALCVE-2026-14522 Watch | watch | Jul 30, 2026, 10:16 AM | NVDOpen source |
websphere application server vulnerability (CVE-2026-11897)IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. websphere application server | HIGHCVE-2026-11897 Watch | watch | Jul 30, 2026, 10:16 AM | NVDOpen source |
websphere application server vulnerability (CVE-2026-2482)IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. websphere application server | HIGHCVE-2026-2482 Watch | watch | Jul 29, 2026, 2:16 PM | NVDOpen source |
websphere application server vulnerability (CVE-2026-14529)IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled. websphere application server | CRITICALCVE-2026-14529 Watch | watch | Jul 29, 2026, 2:16 PM | NVDOpen source |
websphere application server vulnerability (CVE-2026-15328)IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP request smuggling. websphere application server | HIGHCVE-2026-15328 Watch | watch | Jul 28, 2026, 4:17 PM | NVDOpen source |
websphere application server vulnerability (CVE-2026-14976)IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature enabled. websphere application server | CRITICALCVE-2026-14976 Watch | watch | Jul 28, 2026, 4:17 PM | NVDOpen source |
websphere application server vulnerability (CVE-2026-14974)IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data. websphere application server | CRITICALCVE-2026-14974 Watch | watch | Jul 28, 2026, 4:17 PM | NVDOpen source |
aspera faspex vulnerability (CVE-2026-14959)IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to shell command injection. aspera faspex | HIGHCVE-2026-14959 Watch | watch | Jul 28, 2026, 4:17 PM | NVDOpen source |
aspera faspex vulnerability (CVE-2026-14958)IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation. aspera faspex | HIGHCVE-2026-14958 Watch | watch | Jul 28, 2026, 4:17 PM | NVDOpen source |
websphere application server vulnerability (CVE-2026-14528)IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive information. websphere application server | HIGHCVE-2026-14528 Watch | watch | Jul 28, 2026, 4:17 PM | NVDOpen source |
websphere application server vulnerability (CVE-2026-16184)IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request. websphere application server | CRITICALCVE-2026-16184 Watch | watch | Jul 28, 2026, 3:17 PM | NVDOpen source |
api connect vulnerability (CVE-2026-9074)IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset functionality. api connect | CRITICALCVE-2026-9074 Watch | watch | Jul 8, 2026, 11:16 AM | NVDOpen source |
Vendor watch hub
The IBMwatch hub is a vendor-specific view inside ITECS MSP Threat Radar. We pull the latest security advisories, incidents, and known-exploited CVEs directly from the official feeds below, score each one for MSP relevance, and surface what's most likely to need attention this week.
At a glance
Tracked
Active
Featured
Unique CVEs
Most recent entry
Aug 5, 2026, 12:16 PM
Feed refreshes daily · 5:15 a.m. Central
Sources·CISA KEV and NVD (product vendor coverage)
"Most recent entry" is the newest item the upstream feed has published — not our sync time.
Related vendors
ITECS response pathways
These pathways connect the vendor watch feed into service-owner resources that already carry commercial authority.
Use the cybersecurity services pathway when this vendor alert needs an ITECS-managed response plan.
Connect the vendor watch page to broader managed detection, response, and governance planning.
Translate current watch items into a faster risk snapshot and prioritized remediation plan.
Return to the hub for cross-vendor prioritization, live filtering, and broader MSP threat context.
Vendor watch FAQ
It is the IBM-specific view inside ITECS Threat Radar, built to track recent advisories, incidents, and watch items that may affect Dallas-area business operations.
Use it to confirm whether current IBM issues overlap with your environment, prioritize remediation, and decide whether you need an assessment, managed security follow-through, or vendor-specific hardening work.
Yes. ITECS can help map IBM advisories against your systems, validate affected services, prioritize remediation, and connect the issue to broader managed cybersecurity or managed IT workflows.