LIVE · cybersecurity feed
Live wire
vendor

Ibm

300 CVEs published in the last four months and 2 stories. Exploited flaws first.

Critical70
High230
Medium0
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-168169.9criticalviosIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary com17d ago
CVE-2026-171869.9criticaldb2 mirror for iIBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to impro22d ago
CVE-2026-168609.9criticaliIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an uncon24d ago
CVE-2026-150689.9criticalviosIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote authenticated attacker to execute arbitrary17d ago
CVE-2026-188359.9criticalviosIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary com16d ago
CVE-2026-171529.8criticalviosIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buf16d ago
CVE-2026-171459.8criticalviosIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to impro16d ago
CVE-2026-171429.8criticalviosIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to i16d ago
CVE-2026-171419.8criticalviosIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buf16d ago
CVE-2026-171369.8criticalviosIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a for16d ago
CVE-2026-171229.8criticalviosIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a sta16d ago
CVE-2026-171189.8criticalviosIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a use16d ago
CVE-2026-170409.8criticalviosIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buf16d ago
CVE-2026-129439.8criticalhardware management consoleIBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Po37d ago
CVE-2026-169199.8criticalaixIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to impro17d ago
CVE-2026-169179.8criticalviosIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an in17d ago
CVE-2026-169139.8criticalviosIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a sta17d ago
CVE-2026-168949.8criticalviosIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a sta17d ago
CVE-2026-168859.8criticalviosIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a sta17d ago
CVE-2026-168829.8criticalviosIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to i17d ago
CVE-2026-168729.8criticalviosIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a sta17d ago
CVE-2026-168649.8criticalviosIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a sta17d ago
CVE-2026-168629.8criticalaixIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a sta17d ago
CVE-2026-168459.8criticalaixIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a hea17d ago
CVE-2026-168349.8criticalaixIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an17d ago
CVE-2026-169569.8criticaldb2 mirror for iIBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary commands due to improper24d ago
CVE-2026-172189.8criticaliIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write24d ago
CVE-2026-154359.8criticalapp connect enterpriseIBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacke37d ago
CVE-2026-145129.8criticalwebsphere application serverIBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserializati39d ago
CVE-2026-166569.8criticalviosIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to gain root privileges due to imprope17d ago
CVE-2026-86339.8criticalwebsphere application serverIBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application S102d ago
CVE-2026-170839.8criticaliIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a stack-based buffer o24d ago
CVE-2026-168409.8criticalaixIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an ou17d ago
CVE-2026-91709.8criticalhttp serverIBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service and a potential remote code execution due to improp102d ago
CVE-2026-171579.8criticalviosIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a sta16d ago
CVE-2026-36609.8criticalengineering lifecycle managementIBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an unauthenticated remote attacker to upda102d ago
CVE-2026-171849.8criticaldb2 mirror for iIBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external con22d ago
CVE-2026-171829.8criticaldb2 mirror for iIBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter 22d ago
CVE-2026-81759.8criticalaspera high-speed transfer endpointIBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.101d ago
CVE-2026-171609.8criticalviosIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an in16d ago
CVE-2026-174829.8criticaldocumentation offlineIBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to impro23d ago
CVE-2026-144469.8criticalwebsphere application serverIBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the a39d ago
CVE-2026-101099.8criticaldb2IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution due to improper pr67d ago
CVE-2026-121189.8criticalwebmethods integrationIBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitr37d ago
CVE-2026-169039.6criticalviosIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code or cause a d17d ago
CVE-2026-168359.6criticalpower system e1080 \(9080-hex\) firmwareIBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 throu17d ago
CVE-2026-166879.6criticalpower system e1180 \(9080-heu\) firmwareIBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 throu17d ago
CVE-2026-172769.6criticaliIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to escalate privileges due to improper au24d ago
CVE-2026-145299.4criticalwebsphere application serverIBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.038d ago
CVE-2026-145259.4criticalwebsphere application serverIBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is v23d ago
CVE-2026-168399.4criticalaixIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information due to17d ago
CVE-2026-117129.3criticalwebsphere application serverIBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administr67d ago
CVE-2026-150919.3criticalengineering ai hubIBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to i50d ago
CVE-2026-117089.3criticalwebsphere application serverIBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administr67d ago
CVE-2026-174229.3criticalviosIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a buff16d ago
CVE-2026-171819.3criticaldb2 mirror for iIBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due to 22d ago
CVE-2026-149739.3criticalasperaIBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the us39d ago
CVE-2026-168229.3criticalaixIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to impersonate the TNC policy server a17d ago
CVE-2026-117079.3criticalwebsphere application serverIBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-s37d ago
CVE-2026-36279.1criticalconcertIBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection.8d ago
CVE-2026-86449.1criticalwebsphere application serverIBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.96d ago
CVE-2026-150659.1criticalviosIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to bypass security restrictions du17d ago
CVE-2026-126289.1criticalstorage protectIBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 through 8.75d ago
CVE-2026-78769.1criticalaspera high-speed transfer server for cloud pak for integrationIBM Aspera HSTS for CP4I 1.5.1 through 1.5.19 is affected by an authentication bypass vulnerability.101d ago
CVE-2026-149599.1criticalaspera faspexIBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code d39d ago
CVE-2026-169269.1criticalviosIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary files due to im16d ago
CVE-2026-90749.1criticalapi connectIBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection v59d ago
CVE-2026-149589.1criticalaspera faspexIBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code d39d ago
CVE-2026-93199criticalwebsphere application serverIBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserializati96d ago
CVE-2026-93119criticalwebsphere application serverIBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of securi96d ago
CVE-2026-180998.9highiIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary script code due to i24d ago
CVE-2026-181938.9highiIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validat23d ago
CVE-2026-168488.8highaixIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to i17d ago
CVE-2026-194498.8highviosIBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a vulnerability in cmdnim that may allow an unprivileged local u16d ago
CVE-2026-50658.8highcontrollerIBM Controller 11.0.1, 11.1.0, 11.1.1, and 11.1.2 contains hard-coded credentials, such as a password or cryptograp101d ago
CVE-2026-81798.8highaspera high-speed transfer endpointIBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.101d ago
CVE-2026-77708.8highi access client solutionsIBM i Access Family 1.1.5.0 through 1.1.9.12 IBM i Access Client Solutions (ACS) is vulnerable to remote code execu96d ago
CVE-2026-78708.8highiIBM i 7.6, 7.5, 7.4, and 7.3 could allow a user to gain elevated privileges due to an unqualified library call.86d ago
CVE-2026-145228.8highapp connect enterpriseIBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacke37d ago
CVE-2026-186838.8highiIBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to privilege escalation via Navigator for i.24d ago
CVE-2026-188478.8highiIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to harvest credentials due to spoofing 24d ago
CVE-2026-168568.8highiIBM i 7.6, and 7.5 could allow a local attacker to gain elevated privileges due to improper neutralization of spec24d ago
CVE-2026-169068.8highiIBM i 7.6, and 7.5 could allow a remote authenticated attacker to execute arbitrary commands with elevated privile24d ago
CVE-2026-171108.8highiIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands and obtain 24d ago
CVE-2026-186698.8highiIBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to a privilege escalation as the result of a remote code execution vuln24d ago
CVE-2026-187138.8highiIBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to privilege escalation via Navigator for i.24d ago
CVE-2026-133618.8highinformix dynamic serverIBM Informix oninit sq_sgkprepare RCE via unchecked SQL Interface length field.24d ago
CVE-2026-170828.8highiIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improp24d ago
CVE-2026-174178.8highiIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to impr24d ago
CVE-2026-176428.8highiIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to impr24d ago
CVE-2026-131058.8highi access client solutionsIBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to zip slip path traversal exploit when impor24d ago
CVE-2026-166748.8highiIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an untru23d ago
CVE-2026-167228.8highiIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain unauthorized privileges due to 23d ago
CVE-2026-169758.8highiIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to a heap-b23d ago
CVE-2026-169878.8highiIBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper validation o23d ago
CVE-2026-170298.8highiIBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code due to an out-of-bounds write.23d ago
CVE-2026-172238.8highiIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to a buffer23d ago
CVE-2026-174818.8highdocumentation offlineIBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to impro23d ago
CVE-2026-181018.8highiIBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper management o23d ago
CVE-2026-168798.8highdb2 mirror for iIBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions22d ago

Filter the full tracker by Ibm

Our coverage of Ibm

vulnerabilitycritical

IBM's agentic AI platform is under active attack - patch now

A critical Langflow flaw allowing RCE on default deployments is being exploited, says the CISA

patch

Anthropic's AI Finds Bugs. IBM Bets $5B It Can Fix Them.

IBM and Red Hat assign 20,000 engineers to the new Project Lightwell service as Anthropic's Mythos findings ignite debate over how to secure the open source software supply chain.