CVE-2025-36386Critical· 9.8▾ MidnightIBM Maximo Application Suite 9.0.0 through 9.0.15 and 9.1.0 through 9.1.4 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
IBM Maximo Application Suite 9.0.0 through 9.0.15 and 9.1.0 through 9.1.4 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application.
maximo_application_suite >= 9.0, <= 9.0.15maximo_application_suite >= 9.1.0, <= 9.1.4Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-6266High· 8.3A flaw was found in the AAP gateway
CVE-2026-84862High· 7.2IBM Guardium Data Protection 12.2 is vulnerable to insecure deserialization in the Quartz JDBC job store
CVE-2026-93306High· 7.1IBM Server Firmware FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the ASMI web interface
CVE-2026-84882High· 7.5IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the Universal Connector Oracle Wallet upload component
CVE-2026-93030Medium· 6.5FTM 4.x ALL could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity injection flaw.
CVE-2026-85542High· 8.8IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the GIM bundle import functionality