De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
Serial number: AV26-922Date: September 15, 2026 As of September 14, 2026, IBM is affected by vulnerabilities in the following products: Langflow OSS Prior to or equal to 1.10.0 Prior to or equal to 1.10.2 Prior to or equal to 1.11.2 Prior to or equal to 1.11.5 MQ 10.0.0.0 Prior to or equal to 9.1.0.37 LTS Prior to or equal to 9.2.0.43 LTS Prior to or equal to 9.3.0.41 LTS Prior to or equal to 9.3.5.1 CD Prior to or equal to 9.4.0.25 LTS Prior to or equal to 9.4.5.1 CD Sterling File Gateway…
Aggiornamenti di sicurezza IBM sanano una vulnerabilità, con gravità "alta", nel prodotto Db2, sistema di gestione di database relazionali (RDBMS). Tale vulnerabilità, qualora sfruttata, potrebbe consentire a un attaccante remoto la scrittura di file arbitrari sui sistemi interessati.
De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à l'intégrité des données.
Serial Number: AV26-862Date: August 31, 2026 As of August 28, 2026, IBM is affected by vulnerabilities in the following products: SPSS Collaboration and Deployment Services Multiple versions IBM SPSS Analytic Server Multiple version IBM MQ Agent Multiple versions IBM Maximo Application Suite - Monitor Component Prior to or equal to 9.2, 9.1 and 9.0 IBM Observability with Instana (Agent) Prior to or equal to 1.0.323 IBM Financial Transaction Manager (FTM) for RedHat OpenShift Multiple versions…
De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
IBM heeft kwetsbaarheden verholpen in AIX en PowerVM VIOS. Ook heeft IBM eerdere kwetsbaarheden in, onder andere, DB2, WebSphere, Oracle producten als Java en GraalVM, PostgreSQL, OpenSSH en Perl verholpen voor de producten geproduceerd voor AIX. Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade: - Denial-of-Service - Omzeilen van een beveiligingsmaatregel - Uitvoer van willekeurige code (root/admin-rechten) -…
De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.6, CVEs: CVE-2026-16835, CVE-2026-16832, CVE-2026-18848, CVE-2026-16828, Summary: Links provided for vulnerabilities with CVSS score of >=8. See also: https://www.ibm.com/support/pages/node/7283895, See also: https://www.ibm.com/support/pages/node/7283897, See also: https://www.ibm.com/support/pages/node/7283898
Serial Number: AV26-819Date: August 17, 2026 As of August 14, 2026, IBM is affected by vulnerabilities in the following product: IBM App Connect Operator multiple versions IBM App Connect Enterprise Certified Containers Operands multiple versions Total Storage Service Console (TSSC) / TS4500 IMC multiple versions IBM Tivoli Network Manager IP Edition Prior to or equal to 4.2.0.24 IF1 IBM Tivoli Monitoring Prior to or equal to 6.3.0.7 Service Pack 23 PowerVC Prior to or equal to 2.3.1, 2.3.2 and…
IBM heeft kwetsbaarheden verholpen in IBM i operating system versies 7.3, 7.4, 7.5 en 7.6. De kwetsbaarheden betreffen meerdere aspecten van het IBM i - operating system, waaronder onjuist privilege management, onbeheerde zoekpadelementen, out-of-bounds reads en writes, buffer overflows (zowel heap- als stackgebaseerd), SQL-injecties, path traversal, TOCTOU-racecondities met symbolische links, onjuiste validatie van omgevingsvariabelen en profielnamen, en onjuiste neutralisatie van speciale…
De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
IBM ha pubblicato aggiornamenti di sicurezza per risolvere molteplici vulnerabilità, di cui 9 con gravità "critica" e 48 con gravità "alta", nei prodotti Db2, Security Verify Access, Verify Identity Access, WebSphere e IBM i.
Serial Number: AV26-789Date: August 10, 2026 As of August 7, 2026, IBM is affected by vulnerabilities in the following products: Application Gateway Operator Prior to or equal to 26.06 Big SQL on IBM Cloud Pak for Data Version Big SQL 7.7 on Cloud Pak for Data 5.0 Big SQL on IBM Software Hub Multiple versions Business Automation Workflow containers and traditional 26.0.0 Prior to or equal to 24.0.0 Interim Fix 009 Prior to or equal to 24.0.1 Interim Fix 007 Prior to or equal to 25.0.0 Interim…
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-9198 IBM Langflow Code Injection Vulnerability CVE-2026-18556 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability CVE-2026-34486 Apache Tomcat Missing Encryption of Sensitive Data Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the…
A quarterly look at Elastic’s security integrations ecosystem Security teams can only protect what they can see. Gaps in coverage, like a macOS fleet generating logs that never reach your SIEM, an email gateway running in isolation, or a cloud environment producing findings that stay siloed in the vendor console, are easily exploited by attackers. Elastic’s answer to this is continuous and open investment in third-party integrations, built on the belief that a strong security ecosystem requires…