IBM threat watch

IBM product CVE coverage for enterprise software, middleware, security tooling, cloud services, and infrastructure components.

Vendor watch hub

What this page covers

The IBMwatch hub is a vendor-specific view inside ITECS MSP Threat Radar. We pull the latest security advisories, incidents, and known-exploited CVEs directly from the official feeds below, score each one for MSP relevance, and surface what's most likely to need attention this week.

  • Confirm whether recent IBM activity overlaps with your environment.
  • Prioritize advisories by MSP-relevance score, severity, and status.
  • Turn the signal into an assessment, briefing, or managed-service engagement with ITECS.

At a glance

Tracked

354

Active

7

Featured

61

Unique CVEs

20

Most recent entry

Jun 1, 2026, 2:16 PM

Feed refreshes daily · 5:15 a.m. Central

Sources·CISA KEV and NVD (product vendor coverage)

"Most recent entry" is the newest item the upstream feed has published — not our sync time.

Watch items

Recent IBM watch items

Showing the 20 most recent items, newest first. Each row links to the official advisory.

20 rows · sorted newest first

Operations view

websphere application server vulnerability (CVE-2026-9330)

HIGH
watchNVDCVE-2026-9330

IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deserialization using the SAML Web Single Sign-On component. This could result in remote code execution via a crafted HTTP request when combined with a suitable gadget chain.

Jun 1, 2026, 2:16 PMOfficial source

websphere application server vulnerability (CVE-2026-9319)

CRITICAL
watchNVDCVE-2026-9319

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS endpoints with WS-Security.

Jun 1, 2026, 2:16 PMOfficial source

websphere application server vulnerability (CVE-2026-9311)

CRITICAL
watchNVDCVE-2026-9311

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls.

Jun 1, 2026, 2:16 PMOfficial source

websphere application server vulnerability (CVE-2026-8644)

CRITICAL
watchNVDCVE-2026-8644

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.

Jun 1, 2026, 2:16 PMOfficial source

aspera high-speed transfer endpoint vulnerability (CVE-2026-8180)

HIGH
watchNVDCVE-2026-8180

IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a potential denial of service in the asperahttpd component. An unauthenticated user can cause the asperahttpd service to crash.

May 27, 2026, 9:17 AMOfficial source

aspera high-speed transfer endpoint vulnerability (CVE-2026-8179)

HIGH
watchNVDCVE-2026-8179

IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a buffer overflow in the asperahttpd component. This vulnerability could allow an authenticated user to execute arbitrary code on the system.

May 27, 2026, 9:17 AMOfficial source

aspera high-speed transfer endpoint vulnerability (CVE-2026-8175)

CRITICAL
watchNVDCVE-2026-8175

IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a buffer overflow in the asperahttpd component. This vulnerability could be exploited to cause a denial of service and potentially lead to authentication bypass or remote code execution.

May 27, 2026, 9:17 AMOfficial source

aspera high-speed transfer server for cloud pak for integration vulnerability (CVE-2026-7876)

CRITICAL
watchNVDCVE-2026-7876

IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19 is affected by an authentication bypass vulnerability. A transfer client may be able to take advantage of this vulnerability to access files in the server's local storage that they should not have access to, when specific restriction settings are not in place.

May 27, 2026, 9:17 AMOfficial source

operations analytics log analysis vulnerability (CVE-2026-7365)

HIGH
watchNVDCVE-2026-7365

IBM Operations Analytics - Log Analysis  and IBM SmartCloud Analytics - Log Analysis uses default passwords default passwords from the manufacturing process for use during the installation process, which could allow an attacker to bypass authentication.

May 27, 2026, 9:17 AMOfficial source

db2 vulnerability (CVE-2026-6938)

HIGH
watchNVDCVE-2026-6938

IBM Db2 12.1.0 through 12.1.4 is vulnerable to authorization bypass when uploading to a remote object storage path with a special query.

May 27, 2026, 9:17 AMOfficial source

db2 vulnerability (CVE-2026-6052)

HIGH
watchNVDCVE-2026-6052

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to running out of memory when executing certain queries with MDC tables.

May 27, 2026, 9:17 AMOfficial source

db2 vulnerability (CVE-2026-6051)

HIGH
watchNVDCVE-2026-6051

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when executing a specially crafted query with a small statement heap.

May 27, 2026, 9:17 AMOfficial source

controller vulnerability (CVE-2026-5065)

HIGH
watchNVDCVE-2026-5065

IBM Controller 11.0.1, 11.1.0, 11.1.1, and 11.1.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.

May 27, 2026, 9:17 AMOfficial source

websphere application server vulnerability (CVE-2026-4410)

HIGH
watchNVDCVE-2026-4410

IBM WebSphere Application Server - Liberty 19.0.0.7 through 26.0.0.5 and IBM WebSphere Application Server 9.0, and 8.5 and WebSphere Application Server Liberty are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.

May 27, 2026, 9:17 AMOfficial source

netezza performance server replication services vulnerability (CVE-2026-3623)

HIGH
watchNVDCVE-2026-3623

IBM Netezza Performance Server Replication Services 3.0.2.0 through 3.0.5.0 allows an attacker with low‑privileged access to escalate their privileges to root. By exploiting this flaw, the attacker can execute root‑level commands, obtain a root shell, and change the root user’s password. Successful exploitation also enables modification or removal of system‑wide files and the installation of persistent backdoors. This results in full system compromise with complete loss of confidentiality, integrity, and availability.

May 27, 2026, 9:16 AMOfficial source

infosphere optim test data fabrication vulnerability (CVE-2026-3366)

HIGH
watchNVDCVE-2026-3366

IBM InfoSphere Optim Test Data Fabrication 1.0.0, 1.0.0.1, 1.0.0.2, 1.0.2, 1.0.2.2, 1.0.2.3, 1.0.2.4, 1.0.2.5, 1.0.2.6, 1.0.2.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system

May 27, 2026, 9:16 AMOfficial source

db2 vulnerability (CVE-2026-1718)

HIGH
watchNVDCVE-2026-1718

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service with a specially crafted query when autonomous transactions are enabled.

May 27, 2026, 9:16 AMOfficial source

cognos analytics vulnerability (CVE-2025-3633)

HIGH
watchNVDCVE-2025-3633

IBM Cognos Analytics 11.2.0, 11.2.4, 12.0, and 12.1.0 and IBM Cognos Transformer 11.2.4, 12.0, and 12.1.0 are vulnerable to cross-site scripting (XSS). This vulnerability allows a remote attacker to inject arbitrary JavaScript code into the web user interface, which may alter the intended functionality and could lead to the disclosure of credentials within a trusted session.

May 27, 2026, 9:16 AMOfficial source

qradar security information and event manager vulnerability (CVE-2024-56462)

HIGH
watchNVDCVE-2024-56462

IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 002 could allow a privileged user to upload a malicious backup archive that could be restored and used to gain access to the underlying operating system.

May 27, 2026, 9:16 AMOfficial source

operations analytics log analysis vulnerability (CVE-2024-40684)

CRITICAL
watchNVDCVE-2024-40684

IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4 IBM SmartCloud Analytics - Log Analysis does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.

May 27, 2026, 9:16 AMOfficial source

Related vendors

Other cloud vendors in the radar

Vendor watch FAQ

Common questions

What is the IBM threat watch page?

It is the IBM-specific view inside ITECS Threat Radar, built to track recent advisories, incidents, and watch items that may affect Dallas-area business operations.

How should teams use the IBM watch page?

Use it to confirm whether current IBM issues overlap with your environment, prioritize remediation, and decide whether you need an assessment, managed security follow-through, or vendor-specific hardening work.

Can ITECS help respond to IBM security issues?

Yes. ITECS can help map IBM advisories against your systems, validate affected services, prioritize remediation, and connect the issue to broader managed cybersecurity or managed IT workflows.