Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

IBM — Vulnerabilities & Security Advisories 4789

Browse all 4789 CVE security advisories affecting IBM. AI-powered Chinese analysis, POCs, and references for each vulnerability.

IBM operates as a multinational technology and consulting corporation, primarily providing enterprise software, hybrid cloud services, and artificial intelligence solutions. Its extensive portfolio, including the Red Hat OpenShift platform and Watson AI suite, creates a broad attack surface that has historically been associated with Remote Code Execution (RCE) vulnerabilities, particularly within web application frameworks and middleware. Cross-site scripting (XSS) and privilege escalation flaws also frequently appear in its legacy enterprise applications and containerized environments. While the company maintains robust security protocols, past incidents have included data breaches affecting customer information and supply chain compromises. The high volume of recorded Common Vulnerabilities and Exposures (CVEs) reflects the complexity and scale of its global infrastructure rather than inherent systemic failure, though it necessitates rigorous patch management and continuous monitoring for enterprise clients relying on its diverse technological stack.

CVE IDTitleCVSSSeverityPublished
CVE-2026-13445 Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints — Langflow OSSCWE-639 8.1 High2026-07-17
CVE-2026-13446 Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints — Langflow OSSCWE-798 9.8 Critical2026-07-17
CVE-2026-13448 Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints — Langflow OSS 8.1 High2026-07-17
CVE-2026-13473 IBM Storage Protect Client is vulnerable to Heap-Based Buffer Overflow — Storage Protect Client 8.1 High2026-07-17
CVE-2026-14499 Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints — Langflow OSSCWE-78 8.8 High2026-07-17
CVE-2026-14501 Use of Potentially Dangerous Functionthat in IBM Db2 Genius Hub — Db2 Genius HubCWE-676 4.3 Medium2026-07-17
CVE-2026-14971 This PowerVM Novalink update is being released to address — PowerVM NovalinkCWE-16 3.9 Low2026-07-17
CVE-2026-14979 IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to XML Entity Expansion attack — Engineering Lifecycle ManagementCWE-776 5.3 Medium2026-07-17
CVE-2026-15069 Multiple Vulnerabilities in IBM Engineering AI hub. — Engineering AI HubCWE-78 5.4 Medium2026-07-17
CVE-2026-15091 Multiple Vulnerabilities in IBM Engineering AI hub. — Engineering AI HubCWE-79 9.3 Critical2026-07-17
CVE-2026-15093 Multiple Vulnerabilities in IBM Engineering AI hub. — Engineering AI HubCWE-601 4.3 Medium2026-07-17
CVE-2026-15322 Multiple Vulnerabilities in IBM Engineering AI hub. — Engineering AI HubCWE-598 7.5 High2026-07-17
CVE-2026-15995 IBM Cognos Analytics 12.1.3 general availability package contains a data integrity issue in the Agentic AI assistant that may cause incorrect report summaries or report-processing errors under concurrent use — Cognos AnalyticsCWE-362 5.4 Medium2026-07-17
CVE-2026-4938 Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access — Verify Identity AccessCWE-863 6.5 Medium2026-07-17
CVE-2026-4942 IBM i is Affected by Algorithm Downgrade in Transport Layer Security [] — iCWE-757 5.9 Medium2026-07-17
CVE-2026-7364 Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access — Verify Identity AccessCWE-601 3.1 Low2026-07-17
CVE-2026-7667 Path Traversal Vulnerability in API Request Component Content-Disposition Header Processing — Langflow OSSCWE-22 8.8 High2026-07-17
CVE-2026-7754 SSRF Protection Configuration Vulnerability — Langflow OSS 7.7 High2026-07-17
CVE-2026-7755 MCP Server Configuration Validator Bypass via File Upload API — Langflow OSS 8.8 High2026-07-17
CVE-2026-7771 IBM® Db2® is vulnerable to a trap when compiling specially crafted statements containing subqueries could lead to a denial of service — Db2CWE-835 5.5 Medium2026-07-17
CVE-2026-7872 Path Traversal Vulnerability in File Component Leading to Arbitrary File Read and Authentication Bypass — Langflow OSSCWE-22 7.5 High2026-07-17
CVE-2026-8056 Parameter Injection Vulnerability in API Graph Execution Engine — Langflow OSSCWE-94 8.8 High2026-07-17
CVE-2026-8476 Disk Cache Deserialization Remote Code Execution Vulnerability — Langflow OSSCWE-502 9.9 Critical2026-07-17
CVE-2026-8481 Remote Code Execution via Code Validation Endpoint — Langflow OSSCWE-94 9.9 Critical2026-07-17
CVE-2026-8505 Authentication Bypass in Webhook Endpoints Allowed Unauthorized Flow Execution — Langflow OSS 9.8 Critical2026-07-17
CVE-2026-8635 Arbitrary Code Execution in Python Interpreter Component — Langflow OSSCWE-94 9.9 Critical2026-07-17
CVE-2026-8859 Path Traversal in APIRequest Component via Content-Disposition Header — Langflow OSSCWE-22 9.9 Critical2026-07-17
CVE-2026-8861 Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access — Verify Identity AccessCWE-209 5.3 Medium2026-07-17
CVE-2026-9103 Unauthenticated Superuser Token Issuance via Auto-Login Endpoint — Langflow OSSCWE-306 9.8 Critical2026-07-17
CVE-2026-9135 Policies Component Dynamic CodeInput Fields Bypass Custom Component Validation — Langflow OSSCWE-94 9.9 Critical2026-07-17

This page lists every published CVE security advisory associated with IBM. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.