ibm
538 known vulnerabilities affecting ibm products.
Products
aix 167
vios 149
i 133
websphere_application_server 40
power_system_e1180_\(9080-heu\) 29
power_system_e1180_\(9080-heu\)_firmware 29
power_system_e1080_\(9080-hex\) 28
power_system_e1080_\(9080-hex\)_firmware 28
power_system_e1150_\(9043-mru\) 25
power_system_e1150_\(9043-mru\)_firmware 25
power_system_e1050_\(9043-mrx\) 25
power_system_e1050_\(9043-mrx\)_firmware 25
power_system_l1022_\(9786-22h\) 25
power_system_l1022_\(9786-22h\)_firmware 25
power_system_l1024_\(9786-42h\) 25
power_system_l1024_\(9786-42h\)_firmware 25
power_system_l1122_\(9856-22h\) 25
power_system_l1122_\(9856-22h\)_firmware 25
power_system_l1124_\(9856-42h\) 25
power_system_l1124_\(9856-42h\)_firmware 25
power_system_s1012_\(9028-21b\) 25
power_system_s1012_\(9028-21b\)_firmware 25
power_system_s1014_\(9105-41b\) 25
power_system_s1014_\(9105-41b\)_firmware 25
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-82107 | Medium | 0.3% | 9.6 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a… | |
| CVE-2026-18905 | Medium | 0.3% | 7.7 | IBM ContextForge MCP Gateway (`mcp-contextforge-gateway`) <= v1.0.6 MCP Context … | |
| CVE-2026-15280 | Medium | 0.3% | 7.5 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 ND Collecti… | |
| CVE-2026-14446 | Medium | 0.3% | 9.8 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access con… | |
| CVE-2026-17248 | Medium | 0.3% | 7.1 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to caus… | |
| CVE-2026-18221 | Medium | 0.3% | 8.1 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized … | |
| CVE-2026-12359 | Medium | 0.3% | 8.1 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access … | |
| CVE-2026-17423 | Medium | 0.3% | 7.7 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to o… | |
| CVE-2026-8644 | Medium | 0.3% | 9.1 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing… | |
| CVE-2026-18193 | Medium | 0.3% | 8.9 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security re… | |
| CVE-2026-18544 | Medium | 0.3% | 8.1 | IBM Portieris 0.5.0 through 0.14.2 could allow a remote authenticated attacker t… | |
| CVE-2026-17099 | Medium | 0.3% | 7.3 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive i… | |
| CVE-2026-18486 | Medium | 0.3% | 8.8 | IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a remote au… | |
| CVE-2026-17186 | Medium | 0.3% | 9.9 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute … | |
| CVE-2026-16928 | Medium | 0.3% | 7.5 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to c… | |
| CVE-2026-18077 | Medium | 0.3% | 7.5 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of … | |
| CVE-2026-18235 | Medium | 0.3% | 8.3 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to exec… | |
| CVE-2026-16184 | Medium | 0.3% | 7.0 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to b… | |
| CVE-2026-17003 | Medium | 0.3% | 7.7 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to c… | |
| CVE-2026-16690 | Medium | 0.3% | 7.5 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to c… | |
| CVE-2026-16706 | Medium | 0.3% | 7.5 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to c… | |
| CVE-2026-16818 | Medium | 0.3% | 7.5 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to c… | |
| CVE-2026-16924 | Medium | 0.3% | 7.5 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to c… | |
| CVE-2026-16926 | Medium | 0.3% | 9.1 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to o… | |
| CVE-2026-12733 | Medium | 0.3% | 7.5 | IBM DataPower Gateway could allow a remote attacker to cause a denial of service… | |
| CVE-2026-16817 | Medium | 0.3% | 7.5 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to c… | |
| CVE-2026-17177 | Medium | 0.3% | 7.5 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a … | |
| CVE-2026-10842 | Medium | 0.3% | 7.5 | IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Serv… | |
| CVE-2026-16842 | Medium | 0.3% | 8.8 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e… | |
| CVE-2026-16844 | Medium | 0.3% | 8.8 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e… | |
| CVE-2026-16848 | Medium | 0.3% | 8.8 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e… | |
| CVE-2026-16961 | Medium | 0.3% | 7.6 | IBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. A remote attacker could s… | |
| CVE-2026-17045 | Medium | 0.3% | 8.1 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perf… | |
| CVE-2026-14525 | Medium | 0.3% | 9.4 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphe… | |
| CVE-2026-14976 | Medium | 0.3% | 7.1 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected… | |
| CVE-2026-17175 | Medium | 0.3% | 7.5 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attack… | |
| CVE-2026-9322 | Medium | 0.3% | 7.5 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv… | |
| CVE-2026-11897 | Medium | 0.3% | 7.5 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerab… | |
| CVE-2026-14973 | Medium | 0.3% | 9.3 | IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow fil… | |
| CVE-2026-18499 | Medium | 0.3% | 8.1 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerab… | |
| CVE-2026-17502 | Medium | 0.3% | 8.6 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of … | |
| CVE-2026-17485 | Medium | 0.3% | 8.2 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of … | |
| CVE-2026-14528 | Medium | 0.3% | 7.4 | IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote a… | |
| CVE-2026-16686 | Medium | 0.3% | 8.2 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to a… | |
| CVE-2026-16841 | Medium | 0.3% | 8.8 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e… | |
| CVE-2026-18716 | Medium | 0.3% | 7.9 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated… | |
| CVE-2026-16901 | Medium | 0.3% | 8.8 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e… | |
| CVE-2026-16903 | Medium | 0.3% | 9.6 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e… | |
| CVE-2026-16909 | Medium | 0.3% | 8.8 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e… | |
| CVE-2026-16879 | Medium | 0.3% | 8.8 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attack… |