VulnSea

IBM has 276 CVEs on record between 2025 and 2026. Disclosure cadence is accelerating: 267 in the last 90 days against 8 in the 90 before. The busiest recent month was September 2026 with 257. The median CVSS is 7.2 (high), with 33 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-78 (26) and CWE-79 (18). Most affected products: Guardium Data Protection (42), i (34), MQ (22).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.2
Publish → KEV
Last 90 days
267 prev 8

Products

  • Guardium Data Protection 42
  • i 34
  • MQ 22
  • WebSphere Application Server 18
  • datastage_on_cloud_pak_for_data 18
  • Verify Identity Access 13
276
Total CVEs
33
Critical
0
CISA KEV
0
Exploited

IBM vulnerabilities

CVEs affecting IBM, newest first. Open any entry for full detail, references, and exploit status.

276 CVEsRSS

CVE-2026-84241High· 8.1
3d ago

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper authorization.

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper authorization.

TwilightIBM · Guardium Data ProtectionEPSS 0.30%via NVD
CVE-2026-84239High· 7.6
3d ago

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.

TwilightIBM · Guardium Data ProtectionEPSS 0.41%via NVD
CVE-2026-84108High· 8.1
3d ago

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of input during web page generation.

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of input during web page generation.

TwilightIBM · Guardium Data ProtectionEPSS 0.40%via NVD
CVE-2026-84106High· 8.9
3d ago

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

TwilightIBM · Guardium Data ProtectionEPSS 0.32%via NVD
CVE-2026-84105High· 7.7
3d ago

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.

TwilightIBM · Guardium Data ProtectionEPSS 0.35%via NVD
CVE-2026-84089High· 7.8
3d ago

IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management.

IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management.

TwilightIBM · Guardium Data ProtectionEPSS 0.11%via NVD
CVE-2026-84086High· 7.2
3d ago

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.

TwilightIBM · Guardium Data ProtectionEPSS 0.65%via NVD
CVE-2026-84085High· 8.1
3d ago

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.

TwilightIBM · Guardium Data ProtectionEPSS 0.32%via NVD
CVE-2026-84084High· 8.8
3d ago

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery (CSRF) vulnerability.

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery (CSRF) vulnerability.

TwilightIBM · Guardium Data ProtectionEPSS 0.18%via NVD
CVE-2026-84083High· 7.8
3d ago

IBM Guardium Data Protection 12.2 is vulnerable to local privilege escalation via the SUID-root nmap_wrapper binary on the Collector appliance

IBM Guardium Data Protection 12.2 is vulnerable to local privilege escalation via the SUID-root nmap_wrapper binary on the Collector appliance. A local attacker with low-privileged access to the Collector can exploit insufficient argumen…

TwilightIBM · Guardium Data ProtectionEPSS 0.11%via NVD
CVE-2026-84082Critical· 9.8
3d ago

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

MidnightIBM · Guardium Data ProtectionEPSS 0.40%via NVD
CVE-2026-84081High· 8.1
3d ago

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper certificate validation.

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper certificate validation.

TwilightIBM · Guardium Data ProtectionEPSS 0.20%via NVD
CVE-2026-84078Critical· 9.9
3d ago

IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet

IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet. An unauthenticated user can access privileged load-balancer operations, potentially resulting in unauthorized actions a…

MidnightIBM · Guardium Data ProtectionEPSS 0.28%via NVD
CVE-2026-84077High· 8.1
3d ago

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery vulnerability.

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery vulnerability.

TwilightIBM · Guardium Data ProtectionEPSS 0.19%via NVD
CVE-2026-84076High· 7.6
3d ago

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.

TwilightIBM · Guardium Data ProtectionEPSS 0.31%via NVD
CVE-2026-84075Critical· 9.9
3d ago

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to missing authentication for the ChangeTrackerServlet.

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to missing authentication for the ChangeTrackerServlet.

MidnightIBM · Guardium Data ProtectionEPSS 0.35%via NVD
CVE-2026-84074High· 8.9
3d ago

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

TwilightIBM · Guardium Data ProtectionEPSS 0.32%via NVD
CVE-2026-84073Critical· 9.1
3d ago

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

MidnightIBM · Guardium Data ProtectionEPSS 0.26%via NVD
CVE-2026-11545Low· 3.7
3d ago

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to obtain sensitive information from the administrative console due to missing authorization checks.

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to obtain sensitive information from the administrative console due to missing authorization checks.

SunlitIBM · WebSphere Application ServerEPSS 0.34%via NVD
CVE-2026-11540Medium· 5.3
3d ago

IBM WebSphere Application Server 9.0 and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet.

IBM WebSphere Application Server 9.0 and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet.

SunlitIBM · WebSphere Application ServerEPSS 0.30%via NVD
CVE-2026-11539Medium· 5.3
3d ago

IBM WebSphere Application Server 9.0 and 8.5 is affected by an authentication bypass vulnerability in the SOAP/JMX connector.

IBM WebSphere Application Server 9.0 and 8.5 is affected by an authentication bypass vulnerability in the SOAP/JMX connector.

SunlitIBM · WebSphere Application ServerEPSS 0.30%via NVD
CVE-2026-11548Medium· 4.8
3d ago

IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability.

IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability.

SunlitIBM · CICS TX AdvancedEPSS 0.23%via NVD
CVE-2026-11711Medium· 6.5
3d ago

IBM WebSphere Application Server 9.0 and 8.5 is affected by a deserialization vulnerability in the Name Service component.

IBM WebSphere Application Server 9.0 and 8.5 is affected by a deserialization vulnerability in the Name Service component.

SunlitIBM · WebSphere Application ServerEPSS 0.38%via NVD
CVE-2026-11710Medium· 6.5
3d ago

IBM WebSphere Application Server 8.5 is affected by an HTTP request smuggling vulnerability due to improper handling of Content-Length headers.

IBM WebSphere Application Server 8.5 is affected by an HTTP request smuggling vulnerability due to improper handling of Content-Length headers.

SunlitIBM · WebSphere Application ServerEPSS 0.28%via NVD
CVE-2026-11722Medium· 4.8
3d ago

IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability.

IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability.

SunlitIBM · CICS TX AdvancedEPSS 0.23%via NVD
CVE-2026-11716High· 7.5
3d ago

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code during queue manager startup due to improper validation of cluster migration data.

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code during queue manager startup due to improper validation of cluster migration data.

TwilightIBM · MQ for HPE NonStopEPSS 0.45%via NVD
CVE-2026-11726High· 8.1
3d ago

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to obtain sensitive information or cause a denial of service due to improper validation of message header offset values.

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to obtain sensitive information or cause a denial of service due to improper validation of message header offset values.

TwilightIBM · MQ for HPE NonStopEPSS 0.46%via NVD
CVE-2026-11727High· 8.1
3d ago

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of queue manager responses when requesting AMS poli…

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of queue manager responses when requesting AMS poli…

TwilightIBM · MQ for HPE NonStopEPSS 0.61%via NVD
CVE-2026-17619High· 8.6
3d ago

IBM Platform RTM is vulnerable to SQL injection

IBM Platform RTM is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

TwilightIBM · spectrum-lsf : IBM Platform RTMEPSS 0.30%via NVD
CVE-2026-17262Medium· 5.4
3d ago

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to improper validation of FTP authentication commands.

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to improper validation of FTP authentication commands.

SunlitIBM · iEPSS 0.19%via NVD
IBM vulnerabilities (CVEs) · VulnSea