Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.5 CVE-2026-13759

IBM WebSphere eXtreme Scale is affected by Insecure Deserilization_CVE-2026-13759

IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 ships three ObjectInputStream subclasses (WsObjectInputStream, ObjectStreamPool$ReusableInputSt...

IBM WebSphere Extreme Scale 8.6.1.0 CVE
HIGH 7.6 CVE-2026-13449

XXE attack in IBM Business Automation Manager Open Editions_CVE-2026-13449

IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XM...

IBM Business Automation Manager Open Editions 9.0.0 CVE
MEDIUM 6.2 CVE-2026-12086

IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to a Insertion of Sensitive Information into Log File Vulnerability_CVE-2026-12086

IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1...

IBM UCD - IBM UrbanCode Deploy 7.2.0 CVE
MEDIUM 6.5 CVE-2026-12085

IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptable to an Insertion of Sensitive Information Into Sent Data vulnerability_CVE-2026-12085

IBM UCD - IBM UrbanCode Deploy 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2....

IBM UCD - IBM UrbanCode Deploy 7.3.0 CVE
MEDIUM 5.4 CVE-2026-12084

IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to a Permissive Cross-domain Security Policy with Untrusted Domains_CVE-2026-12084

IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to...

IBM UCD - IBM DevOps Deploy 8.1.0 CVE
MEDIUM 6.5 CVE-2026-11906

IBM® Db2® federated server is vulnerable to a denial of service due to improper neutralization of special elements in the data query logic of XMLTable-derived columns by autheticated user_CVE-2026-11906

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated use...

IBM Db2 11.5.0 CVE
HIGH 7.2 CVE-2026-11806

IBM WebSphere Application Server Liberty is affected by a an arbitrary file read vulnerability_CVE-2026-11806

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 is affected by an arbitrary file read vulnerability with the restConnector-2.0...

IBM WebSphere Application Server - Liberty 17.0.0.3 CVE
HIGH 8.5 CVE-2026-11714

IBM WebSphere Application Server Liberty is affected by an authorization bypass vulnerability_CVE-2026-11714

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the apiDiscove...

IBM WebSphere Application Server - Liberty 17.0.0.3 CVE
CRITICAL 9.3 CVE-2026-11712

IBM WebSphere Application Server is affected by a cross-site scripting vulnerability_CVE-2026-11712

IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console help system.

IBM WebSphere Application Server 9.0 CVE
CRITICAL 9.3 CVE-2026-11708

IBM WebSphere Application Server is affected by a cross-site scripting vulnerability_CVE-2026-11708

IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console's integrated help s...

IBM WebSphere Application Server 9.0 CVE