VulnSea

ibm has 387 CVEs on record between 2025 and 2026. Disclosure cadence is accelerating: 371 in the last 90 days against 9 in the 90 before. The busiest recent month was September 2026 with 358. The median CVSS is 7.4 (high), with 46 rated critical. 0% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-78 (40) and CWE-22 (21). Most affected products: Guardium Data Protection (49), Financial Transaction Manager (FTM) for RedHat OpenShift (46), i (34).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.4
Publish → KEV
—
Last 90 days
371 prev 9

Products

  • Guardium Data Protection 49
  • Financial Transaction Manager (FTM) for RedHat OpenShift 46
  • i 34
  • DataStage on Cloud Pak for Data 22
  • MQ 22
  • datastage_on_cloud_pak_for_data 22
387
Total CVEs
46
Critical
0
CISA KEV
1
Exploited

ibm vulnerabilities

CVEs affecting ibm, newest first. Open any entry for full detail, references, and exploit status.

387 CVEsRSS

CVE-2026-81626High· 8.6
1w ago

IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Load Balancer Groups component

IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Load Balancer Groups component. An unauthenticated user can inject SQL statements through the Load Balancer Servlet endpoint, potentially resulting i…

▾ TwilightIBM · Guardium Data ProtectionEPSS 0.37%via NVD
CVE-2026-84036High· 7.4
1w ago

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.

▾ TwilightIBM · Guardium Data ProtectionEPSS 0.34%via NVD
CVE-2026-81937High· 7.2
1w ago

IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the import remotelog_config file CLI command

IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the import remotelog_config file CLI command. A highly privileged authenticated user can inject shell commands through the filename parameter, potent…

▾ TwilightIBM · Guardium Data ProtectionEPSS 1.5%via NVD
CVE-2026-18869Medium· 6.4
1w ago

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions and access internal network services due to improper validation of FTP PORT and EPRT commands.

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions and access internal network services due to improper validation of FTP PORT and EPRT commands.

▾ SunlitIBM · iEPSS 0.22%via NVD
CVE-2026-84070High· 8.9
1w ago

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

▾ TwilightIBM · Guardium Data ProtectionEPSS 0.52%via NVD
CVE-2026-84071High· 7.2
1w ago

IBM Guardium Data Protection 12.2 is vulnerable to OS command injection in the Universal Connector plugin upload functionality

IBM Guardium Data Protection 12.2 is vulnerable to OS command injection in the Universal Connector plugin upload functionality. A privileged authenticated attacker can provide a malicious filename that is incorporated into a shell comman…

▾ TwilightIBM · Guardium Data ProtectionEPSS 1.5%via NVD
CVE-2026-84064Critical· 9.9
1w ago

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

▾ MidnightIBM · Guardium Data ProtectionEPSS 0.62%via NVD
CVE-2026-11725High· 8.8
1w ago

IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in MQINQ request processing.

IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in MQINQ request processing.

▾ TwilightIBM · MQEPSS 0.40%via NVD
CVE-2026-11549Medium· 6.5
1w ago

IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a virtual host bypass vulnerability.

IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a virtual host bypass vulnerability.

▾ SunlitIBM · CICS TX AdvancedEPSS 0.23%via NVD
CVE-2026-11538Low· 3.7
1w ago

IBM WebSphere Application Server 9.0 and 8.5 is affected by a log injection vulnerability through crafted LTPA token cookies.

IBM WebSphere Application Server 9.0 and 8.5 is affected by a log injection vulnerability through crafted LTPA token cookies.

▾ Sunlitibm · websphere_application_serverEPSS 0.16%via NVD
CVE-2026-1037Medium· 6.1
1w ago

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the We…

▾ SunlitIBM · Common LicensingEPSS 0.20%via NVD
CVE-2026-1031Medium· 6.1
1w ago

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the We…

▾ SunlitIBM · Common LicensingEPSS 0.20%via NVD
CVE-2026-1030Medium· 4.3
1w ago

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 generates an error message that includes sensitive information about its environment, users, or associated data.

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 generates an error message that includes sensitive information about its environment, users, or associated data.

▾ SunlitIBM · Common LicensingEPSS 0.21%via NVD
CVE-2026-11537Medium· 4.3
1w ago

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet.

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet.

▾ SunlitIBM · WebSphere Application ServerEPSS 0.18%via NVD
CVE-2026-1029Medium· 5.4
1w ago

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the…

▾ SunlitIBM · Common LicensingEPSS 0.16%via NVD
CVE-2026-1025Medium· 6.1
1w ago

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the…

▾ SunlitIBM · Common LicensingEPSS 0.18%via NVD
CVE-2026-11381High· 8.8
1w ago

IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of message distribution list structures.

IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of message distribution list structures.

▾ TwilightIBM · MQ for HPE NonStopEPSS 0.33%via NVD
CVE-2026-11378High· 8.8
1w ago

IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in distribution list processing.

IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in distribution list processing.

▾ Twilightibm · mqEPSS 0.34%via NVD
CVE-2026-11375High· 8.8
1w ago

IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a stack buffer overflow when processing XA transaction identifiers.

IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a stack buffer overflow when processing XA transaction identifiers.

▾ Twilightibm · mqEPSS 0.35%via NVD
CVE-2026-10858Critical· 9.9
1w ago

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer underflow when processing multi-segment messages.

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer underflow when processing multi-segment messages.

▾ MidnightIBM · MQ for HPE NonStopEPSS 0.37%via NVD
CVE-2026-10853High· 7.5
1w ago

IBM MQ could allow an authenticated attacker with cluster access to cause a denial of service or potentially execute arbitrary code due to improper validation of cluster command message lengths.

IBM MQ could allow an authenticated attacker with cluster access to cause a denial of service or potentially execute arbitrary code due to improper validation of cluster command message lengths.

▾ Twilightibm · mqEPSS 0.37%via NVD
CVE-2026-10841Medium· 4.2
1w ago

IBM WebSphere Application Server 8.5, 9.0, and Liberty are vulnerable to HTTP request smuggling.

IBM WebSphere Application Server 8.5, 9.0, and Liberty are vulnerable to HTTP request smuggling.

▾ SunlitIBM · CICS TX AdvancedEPSS 0.16%via NVD
CVE-2026-10751High· 7.5
1w ago

IBM MQ Java and JMS client libraries could allow an authenticated attacker to execute arbitrary code on client applications due to a deserialization filter bypass in exception handling.

IBM MQ Java and JMS client libraries could allow an authenticated attacker to execute arbitrary code on client applications due to a deserialization filter bypass in exception handling.

▾ TwilightIBM · MQEPSS 0.37%via NVD
CVE-2026-10747Critical· 10.0
1w ago

IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication.

IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication.

▾ MidnightIBM · MQ ApplianceEPSS 0.57%via NVD
CVE-2026-10744High· 7.5
1w ago

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to an integer overflow in MQINQ request validation.

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to an integer overflow in MQINQ request validation.

▾ TwilightIBM · MQ for HPE NonStopEPSS 0.27%via NVD
CVE-2026-10575High· 8.8
1w ago

IBM MQ could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to a heap buffer overflow when processing MQPUT operations with malformed distribution headers.

IBM MQ could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to a heap buffer overflow when processing MQPUT operations with malformed distribution headers.

▾ Twilightibm · mqEPSS 0.28%via NVD
CVE-2026-10030High· 7.1
1w ago

IBM MQ Console allows authenticated non-administrative users to create and start queue managers due to improper authorization checks.

IBM MQ Console allows authenticated non-administrative users to create and start queue managers due to improper authorization checks.

▾ TwilightIBM · MQEPSS 0.23%via NVD
CVE-2026-10027High· 8.1
1w ago

IBM MQ could allow a remote attacker to cause a denial of service or execute arbitrary code due to a buffer overflow when processing malformed compressed data on channels configured with compression enabled.

IBM MQ could allow a remote attacker to cause a denial of service or execute arbitrary code due to a buffer overflow when processing malformed compressed data on channels configured with compression enabled.

▾ Twilightibm · mqEPSS 0.38%via NVD
CVE-2025-36421Medium· 5.9
1w ago

IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.

IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.

▾ SunlitIBM · ControllerEPSS 0.16%via NVD
CVE-2025-36178Medium· 5.4
1w ago

IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow an authenticated user to bypass input validation due to improper validation of client-side input of file size.

IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow an authenticated user to bypass input validation due to improper validation of client-side input of file size.

▾ SunlitIBM · ControllerEPSS 0.25%via NVD
ibm vulnerabilities (CVEs) — page 6 · VulnSea