PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-15762 IBM CVE debrief

IBM DataPower Gateway Out-of-bounds Write vulnerability allows remote attackers to execute arbitrary code. Affected versions include 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2. Defenders should assess exposure and prioritize patching due to the critical risk posed by potential remote code execution. This vulnerability has a CVSS score of 9.8 and is considered CRITICAL. The CVE record was published on 2026-10-08T13:32:17.497Z.

Vendor
IBM
Product
DataPower Gateway 10.6CD
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders responsible for IBM DataPower Gateway instances, particularly those in versions 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2, should assess exposure and prioritize patching.

Why it matters

This vulnerability in IBM DataPower Gateway could allow remote attackers to execute arbitrary code, posing a critical risk to affected systems. Defenders should prioritize patching and assess exposure, particularly for versions 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2.

  • Potential remote code execution
  • Need for immediate patching or mitigation
  • Possible disruption to critical infrastructure
  • Verification of affected versions and exposure required

Technical summary

IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 are vulnerable to an out-of-bounds write, potentially allowing remote attackers to execute arbitrary code due to improper input validation. This vulnerability has a CVSS score of 9.8, indicating a critical severity level. Defenders should prioritize patching and assess exposure to mitigate potential risks.

Defensive priority

High

Recommended defensive actions

  • Review and apply patches from IBM
  • Inventory and assess exposure of DataPower Gateway instances
  • Monitor for potential exploitation attempts

Evidence notes

The CVE record and source item provide details on the vulnerability, but limited information is available on exploitation or impact. Defenders should verify affected versions and assess exposure. The CVE Program record and NIST NVD detail page offer official information on the vulnerability. Vendor advisory and patch information are also available.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-15762 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-15762

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-15762 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-15762

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • IBM DataPower Gateway Out-of-bounds Write

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/15xxx/CVE-2026-15762.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://www.ibm.com/support/pages/node/7289775

    Supplemental source - vendor-advisory, patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.