PatchSiren

IBM CVE debriefs · Page 8

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM IBM CVE published 2026-08-05

CVE-2026-7657

IBM Langflow OSS versions 1.0.0 through 1.10.3 are affected by a server-side request forgery (SSRF) vulnerability due to incomplete and ineffective SSRF protection enforcement. This vulnerability could allow attackers to perform unauthorized requests on behalf of the server, potentially leading to security breaches. Organizations using these versions should prioritize patching and review their SSRF protec [truncated]

MEDIUM IBM CVE published 2026-08-05

CVE-2026-10128

IBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated users to exploit a built-in Langflow component, potentially exposing sensitive secrets by reading arbitrary server environment variables, despite security controls intended to disable custom components. This vulnerability could lead to unauthorized access to sensitive information. Affected users should review and update their installations to prev [truncated]

HIGH IBM CVE published 2026-08-05

CVE-2026-9077

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T17:16:57.510Z and has not been modified since then. CVE-2026-9077 affects IBM Langflow OSS 1.0.0 through 1.10.3, allowing remote authenticated attackers to bypass localhost-only restrictions and write arbitrary MCP server configurations to IDE configuration files on the host system. The CVSS scor [truncated]

HIGH IBM CVE published 2026-08-05

CVE-2026-8446

IBM Langflow OSS 1.0.0 through 1.10.3 contain an authentication bypass vulnerability in the Model Context Protocol (MCP) composer endpoint when mcp_composer_enabled=true (default) and projects are configured with auth_type=oauth . This authentication bypass vulnerability allows unauthorized access to affected systems, potentially leading to data breaches or system compromise. The vulnerability affects IBM [truncated]

MEDIUM IBM CVE published 2026-08-05

CVE-2026-7646

IBM Langflow OSS versions 1.0.0 through 1.10.3 are vulnerable to a path traversal attack, allowing users to read arbitrary files from the server filesystem. This is achieved by sending a crafted MCP `resources/read` request with a URL-encoded path traversal sequence in the filename. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. It potentially exposes sensitive information such as the [truncated]

HIGH IBM CVE published 2026-08-05

CVE-2026-17630

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T17:16:44.923Z and has not been modified since then. Organizations using IBM Langflow OSS 1.0.0 through 1.10.3 should be aware of this potential vulnerability and take steps to validate configuration parameters and review compensating controls for exposed systems while remediation is scheduled and [truncated]

HIGH IBM CVE published 2026-08-05

CVE-2026-17623

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T17:16:44.663Z and has not been modified since then. IBM Langflow OSS versions 1.0.0 through 1.10.3 are affected by a vulnerability that allows remote authenticated attackers to execute arbitrary commands due to improper validation of the command field in MCP server configurations. Organizations s [truncated]

HIGH IBM CVE published 2026-08-05

CVE-2026-17617

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T17:16:44.543Z and has not been modified since then. This vulnerability affects IBM Application Gateway Operator 22.2 through 26.06, allowing for Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specified in custom resources. Organizations should review their inventory and [truncated]

HIGH IBM CVE published 2026-08-05

CVE-2026-8400

IBM WebSphere Application Server 8.5, 9.0, and Liberty Continuous delivery are affected by a flaw in the ORB component of IBM SDK, Java Technology Edition. This vulnerability may allow a malicious IIOP server to induce loading and instantiation of arbitrary classes, potentially leading to high impact on confidentiality, integrity, and availability. Administrators and users, operators, and security teams s [truncated]

MEDIUM IBM CVE published 2026-08-05

CVE-2026-18531

IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use of a weak HMAC session signing secret. This vulnerability affects session data integrity and confidentiality. Security teams should review official advisories for scope and severity. Evidence is limited; primary records indicate a weak HMAC session signing secret in these versions. Defen [truncated]

MEDIUM IBM CVE published 2026-08-05

CVE-2026-12762

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T16:16:49.600Z and has not been modified since then. This medium-severity vulnerability affects IBM Cloud Pak For Business Automation versions 24.0.0, 24.0.1, 25.0.0, and 26.0.0, potentially allowing remote attackers to obtain sensitive information exposed in manifest files. Organizations should r [truncated]

LOW IBM CVE published 2026-08-05

CVE-2026-12730

IBM Business Automation Workflow fails to properly verify that the hostname matches the server certificate potentially allowing connections to an attacker-controlled server. This issue arises in versions 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 007, and 24.0.0 through 24.0.0 Interim Fix 009. The vulnerability may impact IBM Business Automation Workflow administrator [truncated]

HIGH IBM CVE published 2026-08-05

CVE-2026-10025

IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event processing pipeline ( q1labs_core.jar ). When at least one log source type is configured to use XML-format property autodetection, the system processes XML-formatted syslog events sent to por [truncated]

Known exploited IBM CVE published 2026-08-04

CVE-2026-9198

IBM Langflow, a code injection vulnerability, allows for potential critical impacts due to its critical severity. Defenders of IBM Langflow deployments should assess exposure and prioritize mitigation. The vulnerability has a CVSS score of 9.8 and is considered critical. The CISA Known Exploited Vulnerabilities catalog and IBM indicate a critical code injection vulnerability in IBM Langflow. This vulnerab [truncated]

HIGH IBM CVE published 2026-07-30

CVE-2026-11536

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T20:16:52.140Z and has not been modified since then. The vulnerability affects IBM WebSphere Application Server 9.0 and 8.5, allowing for remote code execution. Organizations should prioritize patching due to the high CVSS score of 8.5. Evidence is limited to CVE and NVD details.

MEDIUM IBM CVE published 2026-07-30

CVE-2026-10569

IBM UCD and IBM DevOps Deploy are susceptible to an Exposure of Sensitive Information Vulnerability in plugin output logs due to inadequate log management. This exposure could allow an attacker with access to the logs to potentially obtain sensitive values related to that step. The vulnerability has a CVSS score of 4.3 and a severity of MEDIUM. Users and administrators should review log access controls an [truncated]

HIGH IBM CVE published 2026-07-30

CVE-2026-12733

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T19:17:04.867Z and has not been modified since then. IBM DataPower Gateway is affected by a denial of service vulnerability due to improper resource limitations, classified as HIGH severity with a CVSS score of 7.5. Organizations should review official advisories, assess exposure, and prioritize p [truncated]

CRITICAL IBM CVE published 2026-07-30

CVE-2026-12118

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T19:17:04.483Z and has not been modified since then. The vulnerability affects IBM webMethods Integration (on prem) versions 10.15 and 10.11, allowing unauthenticated remote code execution due to deserialization of untrusted data. Organizations should prioritize patching or mitigating this vulnera [truncated]

MEDIUM IBM CVE published 2026-07-30

CVE-2026-10700

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T19:17:02.100Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access control vulnerabilities in its file handling API. The /api/v1/files/images/{flow_id}/{file_name} endpoint does not enforce authe [truncated]

MEDIUM IBM CVE published 2026-07-30

CVE-2026-10695

IBM Db2 12.1.0 through 12.1.4 federated server is vulnerable to a denial of service when running non-fenced federated queries. This issue arises from the server's handling of certain query types, which can lead to a denial of service condition. Security teams managing IBM Db2 federated servers should verify and apply patches to prevent potential denial of service attacks. Teams should review server config [truncated]

HIGH IBM CVE published 2026-07-30

CVE-2026-10535

IBM Db2 is vulnerable to a buffer overflow in the setgid helper db2flacc. This issue affects IBM Db2 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4. The vulnerability could allow an attacker to execute arbitrary code with elevated privileges, potentially leading to significant operational impact. Security teams should review system configurations and prioritize patching. Evidence limits suggest focusing [truncated]

HIGH IBM CVE published 2026-07-30

CVE-2026-12945

IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs through improper access control on log retrieval and unauthenticated build endpoints. This vulnerability, classified as HIGH with a CVSS score of 7.1, affects deployments of IBM Langflow OSS within the specified version range. The vulnerability enables authenticated users to access and manipul [truncated]

HIGH IBM CVE published 2026-07-30

CVE-2026-10842

IBM WebSphere Application Server 8.5, 9.0, and Liberty 17.0.0.3 through 26.0.0.7 are affected by a high-severity vulnerability allowing remote attackers to bypass security constraints. The vulnerability has a CVSS score of 7.5 and a CVSS vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. Organizations should review and apply patches or updates provided by IBM to address the vulnerability. Affected pr [truncated]

HIGH IBM CVE published 2026-07-30

CVE-2026-14522

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2 and 12.0.1.0 through 12.0.12.27 are vulnerable to remote code execution due to improper neutralization of CRLF characters. This CVE record was published on 2026-07-30T15:16:25.693Z. Organizations should review the official CVE record and vendor advisory for affected scope, severity, and guidance. The vulnerability allows remote attackers to execute arbi [truncated]

HIGH IBM CVE published 2026-07-30

CVE-2026-14519

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T15:16:25.547Z and has not been modified since then. The vulnerability affects IBM App Connect Enterprise versions 13.0.1.0 through 13.0.7.2 and 12.0.1.0 through 12.0.12.27, allowing remote attackers to read arbitrary files due to a path traversal vulnerability. This could lead to unauthorized acc [truncated]

HIGH IBM CVE published 2026-07-30

CVE-2026-12947

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27, is vulnerable to sensitive information exposure. A local user could read log files containing potentially sensitive information. The CVE record was published on 2026-07-30T15:16:24.427Z and has not been modified since then. Users, administrators, and security teams should be aware of this vulnerability and take necessar [truncated]

HIGH IBM CVE published 2026-07-30

CVE-2026-11980

The IBM Aspera Desktop App versions 1.0.5 through 1.0.19 are vulnerable to arbitrary code execution due to loading DLL files at start-up. This vulnerability has a high CVSS score of 7.3, indicating a high severity vulnerability. Organizations should take immediate action to inventory and verify their installations, apply vendor remediation if available, and monitor for suspicious activity. The CVE record [truncated]

CRITICAL IBM CVE published 2026-07-30

CVE-2026-11707

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T15:16:24.010Z and has not been modified since then. CVE-2026-11707 is a cross-site scripting vulnerability in the administrative console login page of IBM WebSphere Application Server and IBM Tivoli System Automation Application Manager. The vulnerability has a CVSS score of 9.3 and is classified [truncated]

MEDIUM IBM CVE published 2026-07-30

CVE-2026-11383

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T15:16:23.877Z and has not been modified since then. CVE-2026-11383 is a cross-site scripting vulnerability in the Administrative Console of IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server. The vulnerability has a CVSS score of 5.4 and is classified as MED [truncated]

MEDIUM IBM CVE published 2026-07-30

CVE-2025-36298

The CVE-2025-36298 record details a cross-site scripting vulnerability in the Ebics server component of IBM Sterling B2B Integrator and IBM Sterling File Gateway. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI, potentially altering intended functionality and leading to credentials disclosure within a trusted session. Security teams should review the CVE re [truncated]