PatchSiren cyber security CVE debrief
CVE-2026-15762 IBM CVE debrief
IBM DataPower Gateway Out-of-bounds Write vulnerability allows remote attackers to execute arbitrary code. Affected versions include 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2. Defenders should assess exposure and prioritize patching due to the critical risk posed by potential remote code execution. This vulnerability has a CVSS score of 9.8 and is considered CRITICAL. The CVE record was published on 2026-10-08T13:32:17.497Z.
- Vendor
- IBM
- Product
- DataPower Gateway 10.6CD
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for IBM DataPower Gateway instances, particularly those in versions 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2, should assess exposure and prioritize patching.
Why it matters
This vulnerability in IBM DataPower Gateway could allow remote attackers to execute arbitrary code, posing a critical risk to affected systems. Defenders should prioritize patching and assess exposure, particularly for versions 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2.
- Potential remote code execution
- Need for immediate patching or mitigation
- Possible disruption to critical infrastructure
- Verification of affected versions and exposure required
Technical summary
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 are vulnerable to an out-of-bounds write, potentially allowing remote attackers to execute arbitrary code due to improper input validation. This vulnerability has a CVSS score of 9.8, indicating a critical severity level. Defenders should prioritize patching and assess exposure to mitigate potential risks.
Defensive priority
High
Recommended defensive actions
- Review and apply patches from IBM
- Inventory and assess exposure of DataPower Gateway instances
- Monitor for potential exploitation attempts
Evidence notes
The CVE record and source item provide details on the vulnerability, but limited information is available on exploitation or impact. Defenders should verify affected versions and assess exposure. The CVE Program record and NIST NVD detail page offer official information on the vulnerability. Vendor advisory and patch information are also available.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-15762 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-15762
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-15762 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-15762
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
IBM DataPower Gateway Out-of-bounds Write
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/15xxx/CVE-2026-15762.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://www.ibm.com/support/pages/node/7289775
Supplemental source - vendor-advisory, patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.