---
id: CVE-2026-6928
title: >-
  IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has
  been freed
summary: >-
  IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has
  been freed. This allows an attacker who can influence program execution or
  input may exploit this condition to corrupt memory, cause application crashes,
  or execu…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-416
vendor: IBM
product: Concert
affected:
  - Concert >= 1.0.0 <= 3.0.0
published: '2026-09-23'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T21:17:02.430'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-6928'
references:
  - url: 'https://www.ibm.com/support/pages/node/7288830'
    label: psirt@us.ibm.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-23T21:33:13.534Z'
---

## Overview

IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been freed. This allows an attacker who can influence program execution or input may exploit this condition to corrupt memory, cause application crashes, or execute arbitrary code.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
