Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.5 CVE-2026-11714

IBM WebSphere Application Server Liberty is affected by an authorization bypass vulnerability_CVE-2026-11714

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the apiDiscove...

IBM WebSphere Application Server - Liberty 17.0.0.3 CVE
CRITICAL 9.3 CVE-2026-11712

IBM WebSphere Application Server is affected by a cross-site scripting vulnerability_CVE-2026-11712

IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console help system.

IBM WebSphere Application Server 9.0 CVE
CRITICAL 9.3 CVE-2026-11708

IBM WebSphere Application Server is affected by a cross-site scripting vulnerability_CVE-2026-11708

IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console's integrated help s...

IBM WebSphere Application Server 9.0 CVE
MEDIUM 4.3 CVE-2026-11595

IBM WebSphere Application Server is affected by a Path Traversal vulnerability_CVE-2026-11595

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information from the administrative console's integ...

IBM WebSphere Application Server 9.0 CVE
HIGH 7.1 CVE-2026-11546

IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability_CVE-2026-11546

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCente...

IBM WebSphere Application Server - Liberty 17.0.0.3 CVE
HIGH 8.2 CVE-2026-10564

SSRF Vulnerability in Langflow OSS Legacy Components Bypasses Protection_CVE-2026-10564

IBM Langflow OSS 1.0.0 through 1.9.6 contains a Server-Side Request Forgery (SSRF). The legacy RSSReaderComponent in rss.py and SearXNG component i...

IBM Langflow OSS 1.0.0 CVE
HIGH 8.2 CVE-2026-10560

Unauthenticated Access to Private Flow Build Events and Cancellation in Langflow OSS_CVE-2026-10560

IBM Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerability in /api/v1/build_public_tmp/ endpoints that allows an unauthen...

IBM Langflow OSS 1.0.0 CVE
HIGH 7.1 CVE-2026-10546

DNS Rebinding TOCTOU Bypass of SSRF Protection in Langflow OSS URL Component_CVE-2026-10546

IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the URL component ( src/lfx/src/lfx/components/...

IBM Langflow OSS 1.0.0 CVE
CRITICAL 9.6 CVE-2026-10140

Cross-Tenant API Key Reuse and Billing Fraud in Langflow Voice Mode Subsystem_CVE-2026-10140

IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of API clients across tenant boundaries....

IBM Langflow OSS 1.0.0 CVE
CRITICAL 10 CVE-2026-10134

Unauthenticated Server-Side RCE via PythonCodeStructuredTool in Public Flows_CVE-2026-10134

IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read and modify every flow, convers...

IBM Langflow OSS 1.0.0 CVE