Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

IBM — Vulnerabilities & Security Advisories 5232

Browse all 5232 CVE security advisories affecting IBM. AI-powered Chinese analysis, POCs, and references for each vulnerability.

IBM operates as a multinational technology and consulting corporation, primarily providing enterprise software, hybrid cloud services, and artificial intelligence solutions. Its extensive portfolio, including the Red Hat OpenShift platform and Watson AI suite, creates a broad attack surface that has historically been associated with Remote Code Execution (RCE) vulnerabilities, particularly within web application frameworks and middleware. Cross-site scripting (XSS) and privilege escalation flaws also frequently appear in its legacy enterprise applications and containerized environments. While the company maintains robust security protocols, past incidents have included data breaches affecting customer information and supply chain compromises. The high volume of recorded Common Vulnerabilities and Exposures (CVEs) reflects the complexity and scale of its global infrastructure rather than inherent systemic failure, though it necessitates rigorous patch management and continuous monitoring for enterprise clients relying on its diverse technological stack.

CVE ID Title CVSS Severity Published
CVE-2026-17623 Langflow is affected OS Command Injection in Model Context Protocol features — Langflow OSS CWE-78 8.8 High 2026-08-05
CVE-2026-17630 Langflow is affected by security vulnerabilities in Model Context Protocol features — Langflow OSS CWE-184 7.2 High 2026-08-05
CVE-2026-17626 Langflow is affected by security vulnerabilities in Model Context Protocol features — Langflow OSS CWE-266 8.8 High 2026-08-05
CVE-2026-8446 Langflow is affected by security vulnerabilities in Model Context Protocol features — Langflow OSS CWE-306 7.5 High 2026-08-05
CVE-2026-7646 Langflow is affected by security vulnerabilities in Model Context Protocol features — Langflow OSS CWE-22 6.5 Medium 2026-08-05
CVE-2026-9077 Reliance on Untrusted Inputs in a Security Decision vulnerabilities in Model Context Protocol features — Langflow OSS CWE-807 8.5 High 2026-08-05
CVE-2026-17617 Server-Side Request Forgery (SSRF) in IBM Application Gateway Operator — Application Gateway Operator CWE-918 8.5 High 2026-08-05
CVE-2026-15656 IBM MAS uses axios-1.15.2, protobufjs-8.0.1 and undici-7.26 which is vulnerable to multiple CVEs, and contains vulnerabilities related to missing Secure attribute on mas-redirect-uri cookie and weak HMAC Session Secret — Maximo Application Suite CWE-614 4.3 Medium 2026-08-05
CVE-2026-18531 IBM MAS uses axios-1.15.2, protobufjs-8.0.1 and undici-7.26 which is vulnerable to multiple CVEs, and contains vulnerabilities related to missing Secure attribute on mas-redirect-uri cookie and weak HMAC Session Secret — Maximo Application Suite CWE-330 5.3 Medium 2026-08-05
CVE-2026-10025 IBM QRadar SIEM has an XML External Entity (XXE) injection vulnerability — QRadar CWE-611 8.2 High 2026-08-05
CVE-2026-13477 IBM QRadar SIEM is vulnerable to remote code execution by privileged users — QRadar CWE-78 4.7 Medium 2026-08-05
CVE-2026-8400 Multiple Vulnerabilities in IBM® Java SDK affect IBM WebSphere Application Server and WebSphere Application Server Liberty due to the July 2026 CPU — WebSphere Application Server CWE-470 8.1 High 2026-08-05
CVE-2026-12730 Improper Validation of Certificate with Host Mismatch in IBM Business Automation Workflow containers — Business Automation Workflow containers and traditional CWE-297 3.8 Low 2026-08-05
CVE-2026-12762 Insertion of Sensitive Information into Externally-Accessible File in IBM Business Automation Insights — Cloud Pak For Business Automation CWE-538 5.3 Medium 2026-08-05
CVE-2026-10569 IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an Exposure of Sensitive Information Vulnerability — UCD - IBM UrbanCode Deploy CWE-200 4.3 Medium 2026-07-30
CVE-2026-11536 IBM WebSphere Application Server is affected by a remote code execution vulnerability — WebSphere Application Server CWE-502 8.5 High 2026-07-30
CVE-2026-12946 Remote Code Execution in CUGA Component CodeAgent — Langflow OSS CWE-94 9.9 Critical 2026-07-30
CVE-2026-13444 Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints — Langflow OSS CWE-520 - - 2026-07-30
CVE-2024-25039 IBM Engineering Requirements Management DOORS and DOORS Web Access is affected by multiple vulnerabilities — Engineering Requirements Management DOORS and DOORS Web Access CWE-400 7.5 High 2026-07-30
CVE-2024-40683 IBM Operations Analytics - Log Analysis is affected by a TOCTOU weakness allowing active sessions to persist beyond a password change — Operations Analytics - Log Analysis CWE-613 6.3 Medium 2026-07-30
CVE-2026-10545 IBM Planning Analytics Local is affected by Open Redirect — Planning Analytics Local CWE-601 7.5 High 2026-07-30
CVE-2026-12943 This Power Hardware Management Console update is being released to address — HMC V10.3.1050.0 CWE-78 9.8 Critical 2026-07-30
CVE-2026-12733 IBM DataPower Gateway affected by denial of service — DataPower Gateway 10.6CD CWE-770 7.5 High 2026-07-30
CVE-2025-36374 IBM DataPower Gateway affected by XML external entity injection — DataPower Gateway 10.6CD CWE-611 5.5 Medium 2026-07-30
CVE-2026-12118 IBM webMethods Integration could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data — webMethods Integration (on prem) CWE-502 9.8 Critical 2026-07-30
CVE-2025-0152 IBM Engineering Requirements Management DOORS and DOORS Web Access is affected by multiple vulnerabilities — Engineering Requirements Management DOORS and DOORS Web Access CWE-79 6.1 Medium 2026-07-30
CVE-2026-10535 IBM® Db2® is vulnerable to buffer overflow in setgid helper db2flacc which can lead to privilege escalation and instance compromise from an unprivileged shell — Db2 CWE-121 8.4 High 2026-07-30
CVE-2026-10695 IBM® Db2® is vulnerable to a denial of service when running non fenced federated queries — Db2 CWE-400 6.2 Medium 2026-07-30
CVE-2026-11904 Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access — Verify Identity Access CWE-209 5.3 Medium 2026-07-30
CVE-2026-10700 Broken Access Control Vulnerabilities in Langflow 1.0.0 - 1.8.4 File Handling API Allowed Unauthorized Access to User Files — Langflow OSS CWE-639 6.5 Medium 2026-07-30

This page lists every published CVE security advisory associated with IBM. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.