IBM threat watch

IBM product CVE coverage for enterprise software, middleware, security tooling, cloud services, and infrastructure components.

Watch items

Recent IBM watch items

Showing the 20 most recent items, newest first. Each row links to the official advisory.

20 rows · sorted newest first

Operations view

application gateway operator vulnerability (CVE-2026-17617)

CRITICAL
watchNVDCVE-2026-17617

IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specified in custom resources.

Aug 5, 2026, 12:16 PMOfficial source

websphere application server vulnerability (CVE-2026-8400)

CRITICAL
watchNVDCVE-2026-8400

IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes.

Aug 5, 2026, 11:17 AMOfficial source

qradar security information and event manager vulnerability (CVE-2026-13477)

HIGH
watchNVDCVE-2026-13477

IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input.

Aug 5, 2026, 11:16 AMOfficial source

qradar security information and event manager vulnerability (CVE-2026-10025)

CRITICAL
watchNVDCVE-2026-10025

IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event processing pipeline ( q1labs_core.jar ). When at least one log source type is configured to use XML-format property autodetection, the system processes XML-formatted syslog events sent to port 514 (UDP/TCP) without authentication.

Aug 5, 2026, 11:16 AMOfficial source

IBM Langflow Code Injection Vulnerability

critical
activeCISA KEVCVE-2026-9198

Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.

Aug 3, 2026, 7:00 PMOfficial source

webmethods integration vulnerability (CVE-2026-12118)

CRITICAL
watchNVDCVE-2026-12118

IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

Jul 30, 2026, 2:17 PMOfficial source

db2 vulnerability (CVE-2026-10535)

HIGH
watchNVDCVE-2026-10535

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc.

Jul 30, 2026, 2:17 PMOfficial source

websphere application server vulnerability (CVE-2026-14980)

HIGH
watchNVDCVE-2026-14980

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to perform SSRF attacks with elevated privileges when the collectiveController-1.0 feature is enabled.

Jul 30, 2026, 10:16 AMOfficial source

app connect enterprise vulnerability (CVE-2026-14522)

CRITICAL
watchNVDCVE-2026-14522

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to execute arbitrary commands due to improper neutralization of CRLF characters.

Jul 30, 2026, 10:16 AMOfficial source

websphere application server vulnerability (CVE-2026-11897)

HIGH
watchNVDCVE-2026-11897

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.

Jul 30, 2026, 10:16 AMOfficial source

websphere application server vulnerability (CVE-2026-2482)

HIGH
watchNVDCVE-2026-2482

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

Jul 29, 2026, 2:16 PMOfficial source

websphere application server vulnerability (CVE-2026-14529)

CRITICAL
watchNVDCVE-2026-14529

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled.

Jul 29, 2026, 2:16 PMOfficial source

websphere application server vulnerability (CVE-2026-15328)

HIGH
watchNVDCVE-2026-15328

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP request smuggling.

Jul 28, 2026, 4:17 PMOfficial source

websphere application server vulnerability (CVE-2026-14976)

CRITICAL
watchNVDCVE-2026-14976

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature enabled.

Jul 28, 2026, 4:17 PMOfficial source

websphere application server vulnerability (CVE-2026-14974)

CRITICAL
watchNVDCVE-2026-14974

IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data.

Jul 28, 2026, 4:17 PMOfficial source

aspera faspex vulnerability (CVE-2026-14959)

HIGH
watchNVDCVE-2026-14959

IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to shell command injection.

Jul 28, 2026, 4:17 PMOfficial source

aspera faspex vulnerability (CVE-2026-14958)

HIGH
watchNVDCVE-2026-14958

IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation.

Jul 28, 2026, 4:17 PMOfficial source

websphere application server vulnerability (CVE-2026-14528)

HIGH
watchNVDCVE-2026-14528

IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive information.

Jul 28, 2026, 4:17 PMOfficial source

websphere application server vulnerability (CVE-2026-16184)

CRITICAL
watchNVDCVE-2026-16184

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request.

Jul 28, 2026, 3:17 PMOfficial source

api connect vulnerability (CVE-2026-9074)

CRITICAL
watchNVDCVE-2026-9074

IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset functionality.

Jul 8, 2026, 11:16 AMOfficial source

Vendor watch hub

What this page covers

The IBMwatch hub is a vendor-specific view inside ITECS MSP Threat Radar. We pull the latest security advisories, incidents, and known-exploited CVEs directly from the official feeds below, score each one for MSP relevance, and surface what's most likely to need attention this week.

  • Confirm whether recent IBM activity overlaps with your environment.
  • Prioritize advisories by MSP-relevance score, severity, and status.
  • Turn the signal into an assessment, briefing, or managed-service engagement with ITECS.

At a glance

Tracked

394

Active

7

Featured

82

Unique CVEs

20

Most recent entry

Aug 5, 2026, 12:16 PM

Feed refreshes daily · 5:15 a.m. Central

Sources·CISA KEV and NVD (product vendor coverage)

"Most recent entry" is the newest item the upstream feed has published — not our sync time.

Related vendors

Other cloud vendors in the radar

Vendor watch FAQ

Common questions

What is the IBM threat watch page?

It is the IBM-specific view inside ITECS Threat Radar, built to track recent advisories, incidents, and watch items that may affect Dallas-area business operations.

How should teams use the IBM watch page?

Use it to confirm whether current IBM issues overlap with your environment, prioritize remediation, and decide whether you need an assessment, managed security follow-through, or vendor-specific hardening work.

Can ITECS help respond to IBM security issues?

Yes. ITECS can help map IBM advisories against your systems, validate affected services, prioritize remediation, and connect the issue to broader managed cybersecurity or managed IT workflows.