VulnSea

ibm has 387 CVEs on record between 2025 and 2026. Disclosure cadence is accelerating: 371 in the last 90 days against 9 in the 90 before. The busiest recent month was September 2026 with 358. The median CVSS is 7.4 (high), with 46 rated critical. 0% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-78 (40) and CWE-22 (21). Most affected products: Guardium Data Protection (49), Financial Transaction Manager (FTM) for RedHat OpenShift (46), i (34).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.4
Publish → KEV
—
Last 90 days
371 prev 9

Products

  • Guardium Data Protection 49
  • Financial Transaction Manager (FTM) for RedHat OpenShift 46
  • i 34
  • DataStage on Cloud Pak for Data 22
  • MQ 22
  • datastage_on_cloud_pak_for_data 22
387
Total CVEs
46
Critical
0
CISA KEV
1
Exploited

ibm vulnerabilities

CVEs affecting ibm, newest first. Open any entry for full detail, references, and exploit status.

387 CVEsRSS

CVE-2026-11918Medium· 5.4
1w ago

IBM ContextForge MCP Gateway <= v1.0.4 IBM mcp-context-forge could allow an authenticated user to bypass protection mechanisms due to incomplete recursive inspection of nested payload content.

IBM ContextForge MCP Gateway <= v1.0.4 IBM mcp-context-forge could allow an authenticated user to bypass protection mechanisms due to incomplete recursive inspection of nested payload content.

▾ SunlitIBM · ContextForge MCP GatewayEPSS 0.16%via NVD
CVE-2026-11864Medium· 6.5
1w ago

IBM Cloud Pak for Business Automation 26.0.0 through 26.0.0 Interim Fix 001, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 008, and 24.0.0 through 24.0.0 Interim Fix 009 is vulnerable to an XPath injection vuln…

IBM Cloud Pak for Business Automation 26.0.0 through 26.0.0 Interim Fix 001, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 008, and 24.0.0 through 24.0.0 Interim Fix 009 is vulnerable to an XPath injection vuln…

▾ SunlitIBM · Cloud Pak for Business AutomationEPSS 0.22%via NVD
CVE-2026-11729High· 8.5
1w ago

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to …

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to …

▾ TwilightIBM · MQEPSS 0.31%via NVD
CVE-2026-12358High· 7.5
1w ago

IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.

IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.

▾ TwilightIBM · Verify Identity AccessEPSS 0.39%via NVD
CVE-2026-12742Medium· 5.4
1w ago

IBM Business Automation Workflow containers and traditional could allow an authenticated attacker to trigger restricted import actions due to missing authorization controls.

IBM Business Automation Workflow containers and traditional could allow an authenticated attacker to trigger restricted import actions due to missing authorization controls.

▾ SunlitIBM · Business Automation Workflow containers and traditionalEPSS 0.17%via NVD
CVE-2026-53710Critical· 10.0
1w ago

MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs

MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to 1.0.2, the python_sandbox_server in mcp-servers/python/python_sandbox_server/src/python_sandbox_server/server_fastmcp.py exposes raw geta…

▾ MidnightIBM · mcp-context-forgeEPSS 1.1%via NVD
CVE-2026-13265Medium· 6.8
1w ago

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker wit…

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker wit…

▾ SunlitIBM · MQEPSS 0.22%via NVD
CVE-2026-12759Medium· 6.5
1w ago

IBM Cloud Pak for Business Automation could allow an authenticated user to cause a denial of service due to uncontrolled resource consumption.

IBM Cloud Pak for Business Automation could allow an authenticated user to cause a denial of service due to uncontrolled resource consumption.

▾ SunlitIBM · Cloud Pak for Business AutomationEPSS 0.22%via NVD
CVE-2026-12758Medium· 5.4
1w ago

IBM Cloud Pak for Business Automation could allow a remote attacker to bypass authorization and invoke restricted endpoints due to improper validation of HTTP headers.

IBM Cloud Pak for Business Automation could allow a remote attacker to bypass authorization and invoke restricted endpoints due to improper validation of HTTP headers.

▾ SunlitIBM · Cloud Pak for Business AutomationEPSS 0.18%via NVD
CVE-2026-12756High· 7.1
1w ago

IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection (XXE) attack when processing XML data

IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or co…

▾ TwilightIBM · Business Automation Workflow containers and traditionalEPSS 0.29%via NVD
CVE-2026-12944Critical· 9.6PoC
1w ago

IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components containing socket or urllib imports

IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components containing socket or urllib imports. This enables: (1) AWS credential…

▾ AbyssalIBM · Langflow OSSEPSS 0.39%via NVD
CVE-2026-13277Medium· 4.7
1w ago

IBM Verify Identity Access could allow a remote attacker to conduct phishing attacks, using an open redirect attack

IBM Verify Identity Access could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoo…

▾ SunlitIBM · Verify Identity AccessEPSS 0.28%via NVD
CVE-2026-13276Medium· 6.1
1w ago

IBM Verify Identity Access 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access 10.0.0 through 10.0.9.2 Interim Fix 001 and IBM Verify Identity Access Container 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verif…

IBM Verify Identity Access 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access 10.0.0 through 10.0.9.2 Interim Fix 001 and IBM Verify Identity Access Container 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verif…

▾ SunlitIBM · Verify Identity AccessEPSS 0.24%via NVD
CVE-2026-13272Medium· 5.4
1w ago

IBM Verify Identity Access is missing origin validation which could allow a remote attacker to perform operations as the victim and potentially launch further attacks against the systems.

IBM Verify Identity Access is missing origin validation which could allow a remote attacker to perform operations as the victim and potentially launch further attacks against the systems.

▾ SunlitIBM · Verify Identity AccessEPSS 0.15%via NVD
CVE-2026-13260High· 7.5
1w ago

IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.

IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.

▾ TwilightIBM · Verify Identity AccessEPSS 0.43%via NVD
CVE-2026-13107High· 7.1
1w ago

IBM Business Automation Workflow containers and traditional may use programming model artifacts that are vulnerable to XML Entity Injection attacks by default.

IBM Business Automation Workflow containers and traditional may use programming model artifacts that are vulnerable to XML Entity Injection attacks by default.

▾ TwilightIBM · Business Automation Workflow containers and traditionalEPSS 0.28%via NVD
CVE-2026-12767Medium· 6.5
1w ago

IBM Langflow OSS 1.0.0 through 1.11.5 is vulnerable to server-side request forgery (SSRF)

IBM Langflow OSS 1.0.0 through 1.11.5 is vulnerable to server-side request forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitati…

▾ SunlitIBM · Langflow OSSEPSS 0.22%via NVD
CVE-2026-12765Medium· 6.5
1w ago

IBM Langflow OSS 1.0.0 through 1.10.2 is vulnerable to server-side request forgery (SSRF)

IBM Langflow OSS 1.0.0 through 1.10.2 is vulnerable to server-side request forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitati…

▾ SunlitIBM · Langflow OSSEPSS 0.22%via NVD
CVE-2026-12766Medium· 5.4
1w ago

IBM Langflow OSS 1.0.0 through 1.11.2 is vulnerable to server-side request forgery (SSRF)

IBM Langflow OSS 1.0.0 through 1.11.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating…

▾ SunlitIBM · Langflow OSSEPSS 0.18%via NVD
CVE-2026-12763Medium· 4.2
1w ago

IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to access another user's MCP server context due to improper cache key isolation in the MCP Tools component.

IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to access another user's MCP server context due to improper cache key isolation in the MCP Tools component.

▾ SunlitIBM · Langflow OSSEPSS 0.15%via NVD
CVE-2026-7884Medium· 5.4
1w ago

IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 allows a non-privileged user to edit their given name and surname to include malicious JavaScript code

IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 allows a non-privileged user to edit their given name and surname to include malicious JavaScript code. When an administrator later accesses the user account m…

▾ SunlitIBM · Cognos AnalyticsEPSS 0.23%via NVD
CVE-2026-78415Medium· 5.4
1w ago

IBM Sterling Secure Proxy 6.2.0.0 through 6.2.1.2 could allow a remote authenticated attacker to perform UI spoofing and phishing attacks due to improper neutralization of user-supplied HTML markup.

IBM Sterling Secure Proxy 6.2.0.0 through 6.2.1.2 could allow a remote authenticated attacker to perform UI spoofing and phishing attacks due to improper neutralization of user-supplied HTML markup.

▾ SunlitIBM · Sterling Secure ProxyEPSS 0.31%via NVD
CVE-2026-75792Medium· 4.3
1w ago

IBM Sterling Secure Proxy 6.2.0.0 through 6.2.1.2 could allow a remote authenticated attacker to view administrative user interface components due to client-side authorization bypass.

IBM Sterling Secure Proxy 6.2.0.0 through 6.2.1.2 could allow a remote authenticated attacker to view administrative user interface components due to client-side authorization bypass.

▾ SunlitIBM · Sterling Secure ProxyEPSS 0.36%via NVD
CVE-2026-19290High· 7.5
1w ago

IBM Sterling File Gateway 6.2.0.0 through 6.2.0.6_1, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 could allow a remote attacker to obtain sensitive information due to improper access control.

IBM Sterling File Gateway 6.2.0.0 through 6.2.0.6_1, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 could allow a remote attacker to obtain sensitive information due to improper access control.

▾ TwilightIBM · Sterling File GatewayEPSS 0.40%via NVD
CVE-2026-19280Medium· 5.2
1w ago

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process. An authenticated attacker could leverage this to terminate their own process.

▾ SunlitIBM · iEPSS 0.12%via NVD
CVE-2026-19086Low· 3.3
1w ago

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process. An authenticated attacker could leverage this to terminate their own process.

▾ SunlitIBM · iEPSS 0.12%via NVD
CVE-2026-14277Medium· 6.3
1w ago

IBM i Access Family 1.1.2.0 through 1.1.9.15 could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a session file.

IBM i Access Family 1.1.2.0 through 1.1.9.15 could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a session file.

▾ SunlitIBM · i Access FamilyEPSS 0.50%via NVD
CVE-2026-18069Medium· 6.0
1w ago

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to obtain ownership of arbitrary file system objects due to a time-of-check to time-of-use (TOCTOU) race condition.

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to obtain ownership of arbitrary file system objects due to a time-of-check to time-of-use (TOCTOU) race condition.

▾ SunlitIBM · iEPSS 0.13%via NVD
CVE-2026-14276Medium· 6.3
1w ago

IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a m…

IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a m…

▾ SunlitIBM · i Access FamilyEPSS 0.27%via NVD
CVE-2026-13287High· 7.1
1w ago

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 is vulnerable to an XML external entity i…

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 is vulnerable to an XML external entity i…

▾ TwilightIBM · MQEPSS 0.39%via NVD
ibm vulnerabilities (CVEs) — page 8 · VulnSea