Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

IBM — Vulnerabilities & Security Advisories 4890

Browse all 4890 CVE security advisories affecting IBM. AI-powered Chinese analysis, POCs, and references for each vulnerability.

IBM operates as a multinational technology and consulting corporation, primarily providing enterprise software, hybrid cloud services, and artificial intelligence solutions. Its extensive portfolio, including the Red Hat OpenShift platform and Watson AI suite, creates a broad attack surface that has historically been associated with Remote Code Execution (RCE) vulnerabilities, particularly within web application frameworks and middleware. Cross-site scripting (XSS) and privilege escalation flaws also frequently appear in its legacy enterprise applications and containerized environments. While the company maintains robust security protocols, past incidents have included data breaches affecting customer information and supply chain compromises. The high volume of recorded Common Vulnerabilities and Exposures (CVEs) reflects the complexity and scale of its global infrastructure rather than inherent systemic failure, though it necessitates rigorous patch management and continuous monitoring for enterprise clients relying on its diverse technological stack.

HighCVE-2026-176172026-08-06
Security Bulletin: Security vulnerability has been found in IBM Application Gateway Operator
HighCVE-2026-100252026-08-06
Security Bulletin: IBM QRadar SIEM has an XML External Entity (XXE) injection vulnerability
High2026-08-06
Security Bulletin: IBM MAS uses axios-1.15.2, protobufjs-8.0.1 and undici-7.26 which is vulnerable to multiple CVEs, and
CriticalCVE-2026-129432026-08-03
Security Bulletin: This Power Hardware Management Console update is being released to address CVE-2026-12943
High2026-08-03
Security Bulletin: Broken Access Control Vulnerabilities in Langflow 1.0.0 - 1.8.4 File Handling API Allowed Unauthorize
CriticalCVE-2026-129462026-08-01
Security Bulletin: Remote Code Execution in CUGA Component CodeAgent
High2026-08-01
Security Bulletin: Langflow is affected by remote code execution, denial of service, path traversal, and exposed credent
High2026-08-01
Security Bulletin: Multiple vulnerabilities have been identified in IBM WebSphere Application Server shipped with Tivoli
CriticalCVE-2026-145292026-08-01
Security Bulletin: IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a server-si
MediumCVE-2024-406832026-08-01
Security Bulletin: IBM Operations Analytics - Log Analysis is affected by a TOCTOU weakness allowing active sessions to
MediumCVE-2025-363742026-08-01
Security Bulletin: IBM DataPower Gateway affected by XML external entity injection (CVE-2025-36374)
HighCVE-2026-163082026-08-01
Security Bulletin: IBM Enterprise Build of Quarkus is affected by a DoS vulnerability
MediumCVE-2026-105692026-07-31
Security Bulletin: IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an Exposure of Sensitive Information
HighCVE-2026-127332026-07-31
Security Bulletin: IBM DataPower Gateway affected by denial of service (CVE-2026-12733)
Unknown2026-07-31
Security Bulletin: IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vu
HighCVE-2026-118852026-07-31
Security Bulletin: This Power System update is being released to address CVE-2026-11885
Unknown2026-07-31
Security Bulletin: Langflow is affected by remote code execution, denial of service, path traversal, and exposed credent
HighCVE-2026-129472026-07-31
Security Bulletin: IBM App Connect Enterprise is vulnerable to Confidentiality disclosure on Discovery Connector nodes (
HighCVE-2026-154352026-07-31
Security Bulletin: IBM App Connect Enterprise is vulnerable to arbitrary file write vulnerability (CVE-2026-15435)
HighCVE-2026-118972026-07-31
Security Bulletin: IBM WebSphere Application Server Liberty is affected by a denial of service vulnerability with HTTP/2

Showing up to 20 recent security advisories. View all →

This page lists every published CVE security advisory associated with IBM. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.