Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

IBM — Vulnerabilities & Security Advisories 5232

Browse all 5232 CVE security advisories affecting IBM. AI-powered Chinese analysis, POCs, and references for each vulnerability.

IBM operates as a multinational technology and consulting corporation, primarily providing enterprise software, hybrid cloud services, and artificial intelligence solutions. Its extensive portfolio, including the Red Hat OpenShift platform and Watson AI suite, creates a broad attack surface that has historically been associated with Remote Code Execution (RCE) vulnerabilities, particularly within web application frameworks and middleware. Cross-site scripting (XSS) and privilege escalation flaws also frequently appear in its legacy enterprise applications and containerized environments. While the company maintains robust security protocols, past incidents have included data breaches affecting customer information and supply chain compromises. The high volume of recorded Common Vulnerabilities and Exposures (CVEs) reflects the complexity and scale of its global infrastructure rather than inherent systemic failure, though it necessitates rigorous patch management and continuous monitoring for enterprise clients relying on its diverse technological stack.

CVE ID Title CVSS Severity Published
CVE-2026-14979 IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to XML Entity Expansion attack — Engineering Lifecycle Management CWE-776 5.3 Medium 2026-07-17
CVE-2026-15069 Multiple Vulnerabilities in IBM Engineering AI hub. — Engineering AI Hub CWE-78 5.4 Medium 2026-07-17
CVE-2026-15091 Multiple Vulnerabilities in IBM Engineering AI hub. — Engineering AI Hub CWE-79 9.3 Critical 2026-07-17
CVE-2026-15093 Multiple Vulnerabilities in IBM Engineering AI hub. — Engineering AI Hub CWE-601 4.3 Medium 2026-07-17
CVE-2026-15322 Multiple Vulnerabilities in IBM Engineering AI hub. — Engineering AI Hub CWE-598 7.5 High 2026-07-17
CVE-2026-15995 IBM Cognos Analytics 12.1.3 general availability package contains a data integrity issue in the Agentic AI assistant that may cause incorrect report summaries or report-processing errors under concurrent use — Cognos Analytics CWE-362 5.4 Medium 2026-07-17
CVE-2026-4938 Incorrect Authorization in IBM Verify Identity Access and IBM Security Verify Access — Verify Identity Access CWE-863 6.5 Medium 2026-07-17
CVE-2026-4942 IBM i is Affected by Algorithm Downgrade in Transport Layer Security [] — i CWE-757 5.9 Medium 2026-07-17
CVE-2026-7364 Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access — Verify Identity Access CWE-601 3.1 Low 2026-07-17
CVE-2026-7667 Path Traversal Vulnerability in API Request Component Content-Disposition Header Processing — Langflow OSS CWE-22 8.8 High 2026-07-17
CVE-2026-7754 SSRF Protection Configuration Vulnerability — Langflow OSS 7.7 High 2026-07-17
CVE-2026-7755 MCP Server Configuration Validator Bypass via File Upload API — Langflow OSS 8.8 High 2026-07-17
CVE-2026-7771 IBM® Db2® is vulnerable to a trap when compiling specially crafted statements containing subqueries could lead to a denial of service — Db2 CWE-835 5.5 Medium 2026-07-17
CVE-2026-7872 Path Traversal Vulnerability in File Component Leading to Arbitrary File Read and Authentication Bypass — Langflow OSS CWE-22 7.5 High 2026-07-17
CVE-2026-8056 Parameter Injection Vulnerability in API Graph Execution Engine — Langflow OSS CWE-94 8.8 High 2026-07-17
CVE-2026-8476 Disk Cache Deserialization Remote Code Execution Vulnerability — Langflow OSS CWE-502 9.9 Critical 2026-07-17
CVE-2026-8481 Remote Code Execution via Code Validation Endpoint — Langflow OSS CWE-94 9.9 Critical 2026-07-17
CVE-2026-8505 Authentication Bypass in Webhook Endpoints Allowed Unauthorized Flow Execution — Langflow OSS 9.8 Critical 2026-07-17
CVE-2026-8635 Arbitrary Code Execution in Python Interpreter Component — Langflow OSS CWE-94 9.9 Critical 2026-07-17
CVE-2026-8859 Path Traversal in APIRequest Component via Content-Disposition Header — Langflow OSS CWE-22 9.9 Critical 2026-07-17
CVE-2026-8861 Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access — Verify Identity Access CWE-209 5.3 Medium 2026-07-17
CVE-2026-9103 Unauthenticated Superuser Token Issuance via Auto-Login Endpoint — Langflow OSS CWE-306 9.8 Critical 2026-07-17
CVE-2026-9135 Policies Component Dynamic CodeInput Fields Bypass Custom Component Validation — Langflow OSS CWE-94 9.9 Critical 2026-07-17
CVE-2026-9171 Vulnerabilities in IBM WebSphere Application affects IBM PowerVM Novalink. — PowerVM Novalink CWE-400 7.5 High 2026-07-17
CVE-2026-9198 Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation — Langflow OSS CWE-94 9.8 Critical 2026-07-17
CVE-2026-9202 Unauthenticated User Registration Could Lead to Remote Code Execution — Langflow OSS CWE-306 9.8 Critical 2026-07-17
CVE-2026-9762 IBM® Data Server driver for JDBC and SQLJ is vulnerable to remote code execution when jdbc url is under user control — Db2 CWE-94 7.8 High 2026-07-17
CVE-2026-9074 IBM API Connect SQL Injection — API Connect CWE-89 9.1 Critical 2026-07-08
CVE-2026-3144 IBM API Connect Default Credentials — API Connect CWE-1392 8.1 High 2026-07-08
CVE-2026-11541 Inconsistent Interpretation of HTTP Requests in CICS Transaction Gateway for Multiplatforms. — CICS Transaction Gateway for Multiplatforms CWE-444 7.4 High 2026-06-30

This page lists every published CVE security advisory associated with IBM. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.