IBM threat watch

IBM product CVE coverage for enterprise software, middleware, security tooling, cloud services, and infrastructure components.

Vendor watch hub

What this page covers

The IBMwatch hub is a vendor-specific view inside ITECS MSP Threat Radar. We pull the latest security advisories, incidents, and known-exploited CVEs directly from the official feeds below, score each one for MSP relevance, and surface what's most likely to need attention this week.

  • Confirm whether recent IBM activity overlaps with your environment.
  • Prioritize advisories by MSP-relevance score, severity, and status.
  • Turn the signal into an assessment, briefing, or managed-service engagement with ITECS.

At a glance

Tracked

134

Active

7

Featured

25

Unique CVEs

20

Most recent entry

Apr 30, 2026, 5:16 PM

Feed refreshes daily · 5:15 a.m. Central

Sources·CISA KEV and NVD (product vendor coverage)

"Most recent entry" is the newest item the upstream feed has published — not our sync time.

Watch items

Recent IBM watch items

Showing the 20 most recent items, newest first. Each row links to the official advisory.

20 rows · sorted newest first

Operations view

turbonomic prometurbo agent vulnerability (CVE-2026-6389)

HIGH
watchNVDCVE-2026-6389

IBM Turbonomic prometurbo agent 8.16.0 through 8.17.6 IBM Turbonomic Application Resource Management grants excessive cluster‑wide permissions, including unrestricted read access to all secrets. An attacker that compromises the operator or its service account can exfiltrate sensitive credentials, escalate privileges, and potentially achieve full cluster compromise.

Apr 30, 2026, 5:16 PMOfficial source

i vulnerability (CVE-2026-2311)

CRITICAL
watchNVDCVE-2026-2311

IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 s vulnerable to privilege escalation caused by an invalid IBM i Web Administration GUI authorization check.  A malicious actor could cause user-controlled code to run with administrator privilege.

Apr 30, 2026, 5:16 PMOfficial source

security verify access vulnerability (CVE-2026-1346)

HIGH
watchNVDCVE-2026-1346

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 could allow a locally authenticated user to escalate their privileges to root due to execution with unnecessary privileges than required.

Apr 7, 2026, 8:16 PMOfficial source

security verify access vulnerability (CVE-2026-1343)

HIGH
watchNVDCVE-2026-1343

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 allows an attacker to contact internal authentication endpoints which are protected by the Reverse Proxy.

Apr 7, 2026, 8:16 PMOfficial source

security verify access vulnerability (CVE-2026-1342)

HIGH
watchNVDCVE-2026-1342

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 could allow a locally authenticated user to execute malicious scripts from outside of its control sphere.

Apr 7, 2026, 7:16 PMOfficial source

security verify access vulnerability (CVE-2026-4101)

CRITICAL
watchNVDCVE-2026-4101

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 under certain load conditions could allow an attacker to bypass authentication mechanisms and gain unauthorized access to the application.

Apr 1, 2026, 4:17 PMOfficial source

security verify access vulnerability (CVE-2026-1345)

HIGH
watchNVDCVE-2026-1345

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 could allow an unauthenticated user to execute arbitrary commands as lower user privileges on the system due to improper validation of user supplied input.

Apr 1, 2026, 4:16 PMOfficial source

IBM Aspera Faspex Code Execution Vulnerability

critical
activeCISA KEVCVE-2022-47986

IBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a YAML deserialization flaw. Known ransomware use: Known.

Feb 20, 2023, 6:00 PMOfficial source

IBM InfoSphere BigInsights Invalid Input Vulnerability

critical
activeCISA KEVCVE-2013-3993

Certain APIs within BigInsights can take invalid input that might allow attackers unauthorized access to read, write, modify, or delete data. Known ransomware use: Known.

May 24, 2022, 7:00 PMOfficial source

IBM Data Risk Manager Remote Code Execution Vulnerability

critical
activeCISA KEVCVE-2020-4428

IBM Data Risk Manager contains an unspecified vulnerability which could allow a remote, authenticated attacker to execute commands on the system.�

Nov 2, 2021, 7:00 PMOfficial source

IBM Data Risk Manager Directory Traversal Vulnerability

critical
activeCISA KEVCVE-2020-4430

IBM Data Risk Manager contains a directory traversal vulnerability that could allow a remote authenticated attacker to traverse directories and send a specially crafted URL request to download arbitrary files from the system.

Nov 2, 2021, 7:00 PMOfficial source

IBM Planning Analytics Remote Code Execution Vulnerability

critical
activeCISA KEVCVE-2019-4716

IBM Planning Analytics is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting.

Nov 2, 2021, 7:00 PMOfficial source

IBM Data Risk Manager Security Bypass Vulnerability

critical
activeCISA KEVCVE-2020-4427

IBM Data Risk Manager contains a security bypass vulnerability that could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system.

Nov 2, 2021, 7:00 PMOfficial source

powerkvm vulnerability (CVE-2015-5073)

CRITICAL
watchNVDCVE-2015-5073

Heap-based buffer overflow in the find_fixedlength function in pcre_compile.c in PCRE before 8.38 allows remote attackers to cause a denial of service (crash) or obtain sensitive information from heap memory and possibly bypass the ASLR protection mechanism via a crafted regular expression with an excess closing parenthesis.

Dec 13, 2016, 10:59 AMOfficial source

filenet workplace vulnerability (CVE-2016-3055)

HIGH
watchNVDCVE-2016-3055

IBM FileNet Workplace 4.0.2 before 4.0.2.14 LA012 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Dec 1, 2016, 5:59 AMOfficial source

appscan source vulnerability (CVE-2016-3033)

HIGH
watchNVDCVE-2016-3033

IBM AppScan Source 8.7 through 9.0.3.3 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Dec 1, 2016, 5:59 AMOfficial source

api connect vulnerability (CVE-2016-3012)

HIGH
watchNVDCVE-2016-3012

IBM API Connect (aka APIConnect) before 5.0.3.0 with NPM before 2.2.8 includes certain internal server credentials in the software package, which might allow remote attackers to bypass intended access restrictions by leveraging knowledge of these credentials.

Dec 1, 2016, 5:59 AMOfficial source

tivoli monitoring vulnerability (CVE-2016-2946)

HIGH
watchNVDCVE-2016-2946

Stack-based buffer overflow in the ax Shared Libraries in the Agent in IBM Tivoli Monitoring (ITM) 6.2.2 before FP9, 6.2.3 before FP5, and 6.3.0 before FP2 on Linux and UNIX allows local users to gain privileges via unspecified vectors.

Dec 1, 2016, 5:59 AMOfficial source

tririga application platform vulnerability (CVE-2016-2917)

HIGH
watchNVDCVE-2016-2917

The notifications component in IBM TRIRIGA Applications 10.4 and 10.5 before 10.5.1 allows remote authenticated users to obtain sensitive password information, and consequently gain privileges, via unspecified vectors.

Nov 30, 2016, 2:59 PMOfficial source

ims enterprise suite vulnerability (CVE-2016-2887)

HIGH
watchNVDCVE-2016-2887

IBM IMS Enterprise Suite Data Provider before 3.2.0.1 for Microsoft .NET allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.

Nov 30, 2016, 2:59 PMOfficial source

Related vendors

Other cloud vendors in the radar

Vendor watch FAQ

Common questions

What is the IBM threat watch page?

It is the IBM-specific view inside ITECS Threat Radar, built to track recent advisories, incidents, and watch items that may affect Dallas-area business operations.

How should teams use the IBM watch page?

Use it to confirm whether current IBM issues overlap with your environment, prioritize remediation, and decide whether you need an assessment, managed security follow-through, or vendor-specific hardening work.

Can ITECS help respond to IBM security issues?

Yes. ITECS can help map IBM advisories against your systems, validate affected services, prioritize remediation, and connect the issue to broader managed cybersecurity or managed IT workflows.